dhi.io/pushgateway
1-alpine-fips, 1-alpine3.24-fips, 1.11-alpine-fips, 1.11-alpine3.24-fips, 1.11.3-alpine-fips, 1.11.3-alpine3.24-fips
sha256:571d4fabd232578b406705af94477a57a080961300172b3e70c5f6878dcb09a5
Manifest digest:sha256:d2618a227b14baf52a22ca4536ff1d19d39f5e7a641d54f74d7d2c82f5deac5e
Size
10.02 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:2ee2e82fce691d19fc882c08bac97178b78941d08b039cb0cf1f1226c1e7506c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:8dc550c6069d8dfe7936956edc24821530f381e8704a4c6e67c0f5760c2b6be8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:ef80506d23a71eca6354cff6571cae14c63821393be895ef2d5e95a3b78c1c38 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:a7bb0a9bdfd9192ec4a5274125a7d98745d0d60f36e991e5a0071f0c823abcb3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:7a9f24a0faef287a87a721b14b4329d3f5c0ee479b9d1bde0415d1566e7c3e30 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:869d9a12dfd02647ade7d14f99711e9b4cc5747dd0fe12c5868c778c1b849bc2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:dee504843f5bb5cad286a497aa2f5be61832caa914e3a22cf9f5503be7c96eb3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:f32bd812c106c030dc392cc47d5e6c044ef4a0658cc7cba8adfb311d29e65faf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:1884c1102e258c2e7b9259e82bce7900d147f30c3d671b8bd18e8e398bb6385e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:44f553b4df16cfd389afd783351b9e7412df5148b3bcfeddf0b9b352b2a89ca0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:b2d60cde7c2a64a96276ea4fb1cbd782c210643f78147a5e7b4a2e73e81ea6d7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:6f3d2ad566d1d278f9eed1f0396f5ae0cfc1fd96f67d5cb49275a12339ce98cd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:a1efffe7bcbfa9e0aad750e493ce07489f217fdfc57f48d0f3294a3951f665c5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:2d56904855842f5bf6066c0358d39c418097a256ce319f5f47f1d1dd969eac3e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:aec7fe6f7368a515d49446241fecc6118c8a7b03ea632c8c6e19af9ce820b1e3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:bdadad2db9cb0ec0af0e0cc3dbfac456fd81a602e4b15107eae3090a7e5318f1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:b1c1fced3603fdbed00b370054946bdfa4f9bed04203efb3f25ad095c77059db |