Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

26-alpine-dev, 26-alpine3.24-dev, 26.4-alpine-dev, 26.4-alpine3.24-dev, 26.4.1-alpine-dev, 26.4.1-alpine3.24-dev

Index digest:

sha256:80c1861d30a677f56769d97e8d331a4dbd940cf90077d14fa55aa0b0abb4d050

Manifest digest:

sha256:66119c1c4c874937e3a6cdcf1b9f72b552a4d6ddb1d763ced4cc22c40c38481d

Size

6.41 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:4ef70752f1b18cf25c15b176391863d95e2cc41bd67baefb48fcd1faca691cbd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:eaecd1e677ce5f7b1f4d88e9a59eb7a6ba98ef82707d0511472e763093017f4d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:a707df0829dca7d54846719392ca70727e502a77d781d8f50a250e0c7ca79db4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:cd2a3b182032f9941a8645b2a1aa11abec08c4af8de7c4f4ef2ede809b74720f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:f61e1828e21be6d6287970a321496334d542092da302e98ab3e54b6b0e06879e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:8fbce194f55330a3e424989a444e7cb5942192b273b45645d1d3d814c2ce0d4f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:c868b7c0a006e4cbfff47315cbdfea3f132ef139ba5084bcb24788d064da5754
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:caa4eea74e64893a2984af4343ac16bd1e4a232c536b059c4552c1ab99d69fb5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:dd61015592b7595a20bf214b00d5089caba8b527be4f1527a9345c47926087ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:136f03e50b1cd2b2ccbd7f51ec3ef62a1e502b146c4cfda5bfadc29f5502e006
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:b155253ca47a3a6d2db7206cff755b1b99a700ccf5bd61a957158cfdd899eebe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:05c26149351a6c3b67403492618b1136ac9c60839e8d7892c3b210d3da6ca493
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:a2bcf103c67ebb7b45fee5b504bd7790d89f40c2f210754c1e4a7bf5301638bb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:f3686dad9dceeb21baf349dda55ab198b7a70ec4448f90ad4f71683799a3a8fd