Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.4, 26.4-debian, 26.4-debian13, 26.4.1, 26.4.1-debian, 26.4.1-debian13

Index digest:

sha256:c37f9591aebd77afbb222666031770de1c49fccd730def2c19fe88e9877ccbc6

Manifest digest:

sha256:ed674d14ff001115c26eb6912bf8fb2c2a82a15cee987eda7b17a95fe3526157

Size

21.40 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:92f7dba2c888f59e59b46bb985ba781de0e29da0fb0a1f1c92fb6fbbdd245b9a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-gateway@sha256:366e509ac6cf965242de905463c31692fbe60e49f0be4f29197a557604bcbcd7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:9373cf9a0c59a042b519ddc9b85bf16c548625c474b0aab3eb77470c7f05f1a2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:4cd81f63b10fb9af3429d127ef345db1bf49e3de3dca86d7c946c5573a1f5222
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:c65f9d94dd3f4c6246a7cd591eeb25045702b2e21eb31e7d62689c187786e1f8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:d1746845aa95d3f446c631f6321922b90a278ef3ceb79d7383c617a776342325
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:6d89f9792b497e58987de2e6d01aa35b6ba10acb790827490361a2b749f2aa10
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:afcf5cedf4802b3c33d39ea17d2a8afe744db3979106c81bb7ff1755badb7cc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:d133ff16664622eee4f6c0cdd6ca0f0aece380bdaf3962f20a6bbbafe7023d65
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:19294399d9072f68987dd570704c1f7131b8f72e2248aa8c8cb9861035b619be
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:d1ae28feb1727352e6bf30cac21048ec3ba7a9eb4ff6457cb860ba05f8710d71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:0adf4083b0f36e9d4918edacc22f3de84f84900b45bc36e0a9fef5c3be113bdd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:0f2ca8446168d748fa6adf180c0b4f8267a3830d4d6b547ccc39900bc28d7957
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:4ee9a49e09d56f141ed499277b4b305a64a98c652ab3e68b5b1a4fa2448df1bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:448a6e370141e589152bafcec900fd97e6f292d014344bfdf5593d3489b87424