Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x

CIS
linux/amd64
alpine 3.24
Tags:

26-alpine, 26-alpine3.24, 26.4-alpine, 26.4-alpine3.24, 26.4.1-alpine, 26.4.1-alpine3.24

Index digest:

sha256:08387e11f203b3cbc0d40f9f73828950e21c24b28a510b915e4a5a034b78be0c

Manifest digest:

sha256:6266788c1b5a3b776bf802975cb1d7f1e5f517ca0afb2b59ebd9fe2ee5834652

Size

6.01 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:0d462ba5526159e3136614ab152938aa98b9a22b1cbe5443f328adfd765e136c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:fe6159a968898df331a97ddc688dc334fc53f27f6e6a24a58bc0e3e9b779ba41
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:f42449e239c689b1ac21ec28a071c106df57294bfa229e509aef4e6e92e9a397
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:ca0a4c106f07cc11076ee5fc90c484b90ea962480ac782fabce356bd42044821
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:ccfdfb8ffd555fc87f8f02ee5a8a78f5782782d0203fa9be606b2f5b90ff55cb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:43ce795eaec728300920bcfd2365e583b9c04ceed65d5b1297d0038f9ac45d97
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:f16e542f33c4e841867532a53e2082c404d25934475277a20bc0c7e4d11c980b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:e7cdc926b0b9c68667568dc2cdbb64870daeb2498c81d9da1881b28b2b8c758d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:a2026e94655a027e7619a8efbd7fc648e366815fd308dfeb4142c4f49bda7e48
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:3dce058d9072adb2bf684799cc1a689459bc909a4c0b9523917d5c4b9d815787
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:1c798e18b780f9b177349c8052910fd14612793f25aba18312ba26fdd57e36f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:ea6ec4a89bdbed3066e476f7a0c1c712df5a8b6dc0f06a0aef33d7ccc2872d17
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:860e2efad9589f017106325f3905eac73bd01b18e99986c9301a1ec67e8a5256
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:0623324d52926e74a6b7f78c4cac1cc1cb08b53a581a1495e57a45772ab62e34