Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.15-debian-fips, 1.15-debian13-fips, 1.15-fips, 1.15.3-debian-fips, 1.15.3-debian13-fips, 1.15.3-fips

Index digest:

sha256:48e0657b41909c15c1deaae22b3492b5c16cb827ace28828ee1d5a19cc8b296a

Manifest digest:

sha256:11b013b66b3c071d126928c98790a27ccbe08042cda429c358ea027d3815fc3a

Size

56.33 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.15-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.15-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:bb92622b9b9eaf4fb87ebff7e546085c42e1319d201eb7751e25b4fe7074df6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:5998842d2cbff9df677936ed924a7a817218a03061293b525d37e82025132f3e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:c492cd6e57344a53224846850377a29bc789bd774f5004b770837fbb3be0f59d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:8165e8cbf0582d15d882c16dc88576f319bdc86b6b661c220174933bfd35d41c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:739a8eaf3a25f6a4a535db980a147e99bc53153a132f455e1adc4b59d8bf0583
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:32a3bc858da8fdb87bd2ace1ad5e40f7455ecbc9a764de1f4349e57b3710fbe6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:edf8ed2f0da7f0d710599ad7bb8cc12dded840157a18ace05f85f9fd5c5a7355
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:7b315f4f0738dde36773162d3e97ccd96ebd8386fc6ba3bc227bcb8d1f294ef3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:8123f64407b2c49b140a31088ea38b749b06b4b2ae9c6f6e6031e606dd718023
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:e792b6835d1f008914ba089b1079ba6bf62f9c8f0e18c6439e0ca7f2379578af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:ab603fb321b1cbc00d70f9e0e95ddcc106cfed2afe5ae406fae8d9674e9ca686
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:a2c493c5e1552cfbaae1329d12cf311340555c9f3e8db147b82b5d4f65a46c0c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:64bcdf180ddb72305f7b7587b4da44b4c00aba1b2e2cdaa2613ea7766f62bd96
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:857419cd03ef30df42b97bbac44f69c0dff3e70e1ff11c31f8a4a605361243fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:50acdc57e70bb5fd8a4d920e8475d89d80d1f6b0e93205148ceaccc58e2f4c1c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:48b368c313267da2582a852cd5fc7525f335ea1be000e7a130840398230659e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:483597af041eab0a219a77a6eb7f0d80e57ee6cde0c4b970709001ed2c3904e1