Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

26-alpine-fips-dev, 26-alpine3.24-fips-dev, 26.4-alpine-fips-dev, 26.4-alpine3.24-fips-dev, 26.4.1-alpine-fips-dev, 26.4.1-alpine3.24-fips-dev

Index digest:

sha256:14454c9bdde80815316f7e956c259068b7eb85d9b5d5618d3081fa070e3e8da7

Manifest digest:

sha256:7d5df1439ebf6a78c254e6350ec555a25746c6bbe2c1e887344598583338cbcf

Size

7.26 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:17ac0aa0c89b2d1b8f093c1d3fe4244f68208f93be05ccfb9fa983d64aba3315
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/codecov-gateway@sha256:23c32e9ce80641f884bf80cc27c35cc4d4fdd1b3bc37fdb26371d7f35bfddf87
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:9a16cba3f335cb584a099877293d9c34ea9fb9a64418d6d4f0c26a16b5024a34
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/codecov-gateway@sha256:c7f5bb0fc09ab7a83d1817ed429ad6787a94f513b20e5cbe37d09b0319eb5494
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:9c1f4940c65a1a757eedf5d7d36065a2ba373892b69e8cc5bb6388bdd36c7bb4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:8834afc23f65c4286798ddbf25edaf55671a27af12b92f3b971f3070d1b7ed85
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:1e26bcf738dfa0c437f2068bf4e4fddffc7d276ec422993ac959e12d4a316e99
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:e5ee36a9e387c70f9bd52fded38ddf87bbce8ff1f2e167e1397a30a00e723119
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:76f28281e6911de64819053ce6143c4bff938631421a2b39272d9d61caa8946d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:eb8904518a4bc6695c0d2e374a810624725ff41e865685054856e34ceb4b2e86
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:5c4616e2925631a3b6093c35a025f5ad61cc320483159b57056d834790461786
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:39799178c687fa4d3a8db1549ad63e84e073fb8575fe6d480dda1c974d38defd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:3f6a412e5d057f59526a45e5fee02c561bac1a35b3c50f72247297a4d3015e8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:0103bf06f5ff300d1b052889bee393f268969757e20b689a32e75dff1fb4f190
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:a0264428a8fa80fa9c9871f775561a981da10b785e7a31dc424b3d0914b57dd0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:eb501b5c9ed23722a750a695eb3af9c127021574f0d88cf823909f4093889f2e