Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.11-alpine3.23, 1.11.3-alpine3.23

Index digest:

sha256:bbd201bc9c9edaa018c4ac174a24675806e2e6ba1013d7b3c40fcae8423b0dcc

Manifest digest:

sha256:ba7f28b2952725069f7abd90aa835d37911c1fd9190d2f215bbc2024423f9dc8

Size

6.63 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:c77f2790841be68ab44b55ae895dc8a8e9db29f3e386d56057ac91fed268dca6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:d1472dd74efa4e9e43da682cfc163d4f0eddaf9c7441c26230dc96fccd8dae65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:07f6f1776a66ddbc65d66bc5f89327741af8a13724ac6f93d7ec6bdab8a4f019
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:68e547732361954a3a77fd5f63cfeb33f6c7987d77a3c7f2c29210ddc8a9b3ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:71ab52f1b494bed86207daff562b24cb318ad52bc577f4bc05d8b95a17c9549a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:ac29faf92b73d2b690443f61ab44ab58a6059cb3949c3335ae5d52cb5c9b26e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:62a18ec772ee37aaa73619affd6ffad5aebc8cf4fdf5e108947b30159e3144f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:d6731dccd7138b12bbc95a76ca63b74ca09488fb98112afd192426df31eaf707
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:27a515e459ec3c9b9819d9506f87ccba2a6ba5da29d15ff409c21c9b43601e59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:62f3fb50df1814ea509b52a567796edc161a9ccf59b8fa6b9635b180f9ec4665
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:527e48da6fb7b1f02d5e567dd670e10e4e8dfebf18ab05a818c78a3d3d00d232
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:2002462f6f997c3ae6b18898876c78c94a63b94939f6fac91c31584d6bb7384e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:d512402ae36195d8a0b41b214c6935abd0eaca11504e8e290b534dc867b59d14
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:f84e13a270890f053699290f8f80b5d1330e08cb8dedd79e6518732761074c17
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:dd0ba4b5ab3f65fdd1bad68b8e4a98c66adcd9f3cebe3021ee7d6c2a34c8a3af