Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

26-alpine-fips, 26-alpine3.24-fips, 26.4-alpine-fips, 26.4-alpine3.24-fips, 26.4.1-alpine-fips, 26.4.1-alpine3.24-fips

Index digest:

sha256:1388b5f3b14576456724a825761acaf415e729041e25429d8f65b3ffc7a316f7

Manifest digest:

sha256:f4f3c500572023c446129bdf00411498966afb445e41c9589dc82275fb5f6736

Size

6.86 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:95da8f8571ba2a06a6e4bb04e038a43d37c74d70b18513a589bf5063c167fae1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/codecov-gateway@sha256:4a72a39a8803f6f61cb66bccf26166cc162e3b8e198ae7f555628fc3bb6d6baa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:fae4e4c54eab6ac811888a7637b2685986cc8a5a552c0d996bff69c35ce63b7d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/codecov-gateway@sha256:d548e12d5cb1e0069902d65a997a938e88e0e314ce6871f8c49eca9f5ac55fe4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:475bde475f02c37439c7a76869315b7a10c77c2237e55a1f4f671d73278106b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:919ba6b9dfd7743050178398c924c866b469ef0302044927fff24bbccc1c180b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:538958f9f1ceec9053d069a04ae6e55cb86b688513cb08b73605ee26dce5e8f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:8b4eb9dcbd0de666bf7846c77b7035b41876e7bfa7af8aefd99be9800bdecbb0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:dda53b876ebed0792d549b2e1058c007d6d9639264bbb0d024a59dd979256fd5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:2f6a0df2f51610f80d389ec42750e9e7265fa70b9c75bab89dc4cc93c5ab6322
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:e4078d7bbb30f6a2d36afefe0e019d4fdd831353b8b9ff9f46345463774eee08
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:17f3b10545493c26b3565611801bd9cd0a0433a4ab13da8889ee5febee9ccba5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:b3cfd6c60b11937006e085af51025cc18bf25e12063d29c00632d52ad09a3844
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:33eebaa8881c4a604e6ad0b5f7f207287e2cb84db7f854db02826b497d935a26
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:643a36322e593cf784b3176a936966df87202ed486c1df916a324665802990a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:496171fafeed8653d74a33c56a99e1b498d852c266c47b38e4ef1091a1bc6965