Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.9-alpine-fips-dev, 0.9-alpine3.24-fips-dev, 0.9.0-alpine-fips-dev, 0.9.0-alpine3.24-fips-dev

Index digest:

sha256:ed2162acd3bac0928b0f49ab74c551107ab04f3be77170eeaf739e93a5051e5a

Manifest digest:

sha256:86af9e388f6e49771aa8f645745941af8b8804512ba74289fb1435697cc3c478

Size

41.44 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:d3b15cc42777263fef6151eb350f5916d912df56dfc3ef44264f2d48cb0c19d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:37dd37e85089519b4b9f3a4d989430a617556225e97365c6244666249b4cfeae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:f07ffd51720dd370b5ea881f74711ff8a0eaadcbafeae0c0f78de885b9d0a1d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:b3b51e851388277beb2ab79a64a2170b71ed53ec7ebf542997e44c01bfdcfe63
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:3fead3fe849f5f9837c25d0dc8c22d33c27159112e4eb66a8dbd4a80a454a40a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:b0b9de0179725e5410fee08e3d627e3afb50c1aa4c860e881add34925ae336ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:3a06734f825d750213aa0d09342573fc9cf921658626d88a146acca39c635500
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:3426f24c7ced744427eb09a00043b3d55378bfeb7a9a5e4432446261a3c56f9d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:696eb25203dcfc7035c5adc48909e99052115e77113d4acd3c2112d96722a1db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:1df88970d949f3926cc29b2d889ce8ff0233cb62bb5ba617aac8dda9606c332b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:07993bd08ff893752564d428636909ecd4087eb06ab41e0dd5b79f584ae66e3c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:cd73f3ceb4846b2ddaf033371b8f6ec9232318240565abe05d9a2dbfe2a06346
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:3d3f281de30835b1f611e42e3de2659d10056923c7d3c2fab154fd7b16f0b50b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:6746ec241a71fd05363d5d474f4386b3fbb1447b73c4eb56d66a76e73f6cb40e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:5c62373475103a97f40da68ccd0ed7e22fc0999061b2eb758a6f716b630d4d6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:48cc31b76a9001c321232ea41925a1eb6fe641f3c825cf588e8147e6ef1c4d58
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:90367ce1ec44d3b0551ded225a99be8f91b095e0989066c8b2f4c77ee810ed65