dhi.io/nginx
1-compat, 1-debian-compat, 1-debian13-compat, 1.31-compat, 1.31-debian-compat, 1.31-debian13-compat, 1.31.6-compat, 1.31.6-debian-compat, 1.31.6-debian13-compat
sha256:50dade2e9ee9991577625438866a51629bd16c13a7369b42bff70da75b2afa78
Manifest digest:sha256:4d65130e34cca111438ca5e92938d39379db8a7e3e1d89f7c4d6747f4a67cc5a
Size
12.09 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/nginx:1-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/nginx:1-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/nginx@sha256:6d1c094a013037b36989e0af47b51ad3092ac1c443c992d201e5ba3ca14b1348 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/nginx@sha256:69a523b019f94c3bed13cb33c68f3f13e0f393d54f81f522f4110cd7e1358711 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/nginx@sha256:c1298ce9ad8c5a62f28e8026f887b42f634f7fbe2f2b9ed9dca754f6968fd4b9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/nginx@sha256:057fc889b16a352941a7fd8ad765b570704540fd0af0376a1723bf69fbb29e9b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/nginx@sha256:922e7c6530e960cf95fc6abbbf8f16785dc7298e1e60b9c6e0c18153dea0f428 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/nginx@sha256:79eedf36cdf4b622939a239ec5c634324167c6f89bb98051e1de0b7afbd09b1c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/nginx@sha256:60c551092c1d72a6f35cdc1bf6650d41802b6237d1fb3b4cc8771dfc0ee72883 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/nginx@sha256:b7d97589bde9094d1b02938c67d14a9280805abb1a499bd6ddf91340061d2eb2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/nginx@sha256:05c51fe10d1330e82f71cee4a0a6d7883ca59d330237c6d02e9aa576930cdd34 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/nginx@sha256:d7800d787037b3f60deb1cb4c37e0a68e80d7126ac4092486d91b784f3bd2b16 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/nginx@sha256:96478ca0b96f039e0280c168cf1065ad2644cb674b8609a93a807d43d63d12ee |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/nginx@sha256:1766db6a21737d580fd71311812c0247d29173d92095153f2ef9ead389b51b8c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/nginx@sha256:c75b26a4cbfb8754d35c17c0b13069ea34cb49c274346ca83e584c76080059a6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/nginx@sha256:189fdb9929ee0a690d202768f79b8fdd7d752455ad28c703e77b06a130bc85bd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/nginx@sha256:95cdb880c3a2494041b887a12f3ee466575eef5b9343df4ddf5820c8cad50773 |