Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.20.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.4-debian-fips, 1.20.4-debian13-fips, 1.20.4-fips

Index digest:

sha256:dda691c38b1de6aae3fcbe917fa36cc14d3058bdbe0e34528fc61398b9ae1c76

Manifest digest:

sha256:41fb2cb76a577d3b0b9538f5ef30a99a49d34e36cf73e702a5bc7af103613bdd

Size

59.29 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.20-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.20-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:0ae803c58af33e1ddaf23cf010027682ec2d672c3992e5499873bb444fbb2c7f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:c7e0fff77579dfb1ab715ed1114480123f6dbd08d3c84d9cf5435f2d82836f6f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:01d667c3f80c599c3b7feaa0c7e9b8d4cd3a94ee6f6600aba755c6486f2238bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:bd279a0363911a0198696dc203f11480a167afee87daab012ebaefe8359b3bff
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:fefbcd8df8775528fa66a5e987fa59542abd7a54747d151f6fd6870780221ef9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:49ca30b22b645525c1b5d41ec17d36ba165f2fe19bb4bb7b6d8b8ed6989c6d47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:da45a6e8654a5c0b00f2967ea166f39585dfcbbf91c7b12d00b810c950c5b168
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:ea1f77320f07e9fdd68239e1b4dee389a3b0642c76556e333b81f171b7a5edd3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:4989aba051182a6738b2bd2d8095c6d164a7de8fa69aa7a6b2bda8ac5f39b93a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:553433d056c829cf18a53f0448639746e6733ff62675390504a09860480c003f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:620974be6b74caec72481c4213d4002163d38aa400ce3bc1871c189c4357f91c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:6212ed593595422ca9ea3839db78137435b23fc7349ba1ab58705f39a54e63c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:9386d11faadbdd9d844aece962a1e4922521583e17da7e6895c0f1980d3af53a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:e1137d97c91b2da6ff972f5a3f6c13867ffb5c2d98a5cd7dff80e46f77c942a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:73022414a0045910279cd5b7e65999ea42a357b1e43b8158fc68a15fe8298eee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:2fa44db17a4b6b458497bdc599fcba571b26866529c70ef6d5148ff8e8d85ba4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:8be8f2961c42b1b130348aace54f8ff6cd4525bf462a73e5f76a2f6e3a7a48b6