dhi.io/codecov-gateway
26-alpine-dev, 26-alpine3.24-dev, 26.4-alpine-dev, 26.4-alpine3.24-dev, 26.4.1-alpine-dev, 26.4.1-alpine3.24-dev
sha256:80c1861d30a677f56769d97e8d331a4dbd940cf90077d14fa55aa0b0abb4d050
Manifest digest:sha256:66119c1c4c874937e3a6cdcf1b9f72b552a4d6ddb1d763ced4cc22c40c38481d
Size
6.41 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/codecov-gateway:26-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/codecov-gateway:26-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/codecov-gateway@sha256:4ef70752f1b18cf25c15b176391863d95e2cc41bd67baefb48fcd1faca691cbd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/codecov-gateway@sha256:eaecd1e677ce5f7b1f4d88e9a59eb7a6ba98ef82707d0511472e763093017f4d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/codecov-gateway@sha256:a707df0829dca7d54846719392ca70727e502a77d781d8f50a250e0c7ca79db4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/codecov-gateway@sha256:cd2a3b182032f9941a8645b2a1aa11abec08c4af8de7c4f4ef2ede809b74720f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/codecov-gateway@sha256:f61e1828e21be6d6287970a321496334d542092da302e98ab3e54b6b0e06879e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/codecov-gateway@sha256:8fbce194f55330a3e424989a444e7cb5942192b273b45645d1d3d814c2ce0d4f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/codecov-gateway@sha256:c868b7c0a006e4cbfff47315cbdfea3f132ef139ba5084bcb24788d064da5754 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/codecov-gateway@sha256:caa4eea74e64893a2984af4343ac16bd1e4a232c536b059c4552c1ab99d69fb5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/codecov-gateway@sha256:dd61015592b7595a20bf214b00d5089caba8b527be4f1527a9345c47926087ab |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/codecov-gateway@sha256:136f03e50b1cd2b2ccbd7f51ec3ef62a1e502b146c4cfda5bfadc29f5502e006 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/codecov-gateway@sha256:b155253ca47a3a6d2db7206cff755b1b99a700ccf5bd61a957158cfdd899eebe |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/codecov-gateway@sha256:05c26149351a6c3b67403492618b1136ac9c60839e8d7892c3b210d3da6ca493 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/codecov-gateway@sha256:a2bcf103c67ebb7b45fee5b504bd7790d89f40c2f210754c1e4a7bf5301638bb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/codecov-gateway@sha256:f3686dad9dceeb21baf349dda55ab198b7a70ec4448f90ad4f71683799a3a8fd |