Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.31, 1.31-debian, 1.31-debian13, 1.31.6, 1.31.6-debian, 1.31.6-debian13

Index digest:

sha256:74581656d727a53e916196d06e9105fbf1b2fb27e201e027d997b250b40b8bcb

Manifest digest:

sha256:becb12682581d34e19feb9315969f79b12c4a4df31119971f2323cd7b9465f0d

Size

10.20 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:579eef50f4488bfb0524c37a7d4186a225b868d1fa8867e2f69878e5b0a33133
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:fb0462f45a5626bc432b75a664c3ac1943a7d5481ee46333715d77528af7e427
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:2d6a47f621cab0fbfc24369cc645330829862bef31f3b0788d306e2899a24025
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:c6d525c38a334ce511ba24f5481ef2cee906d95c4b69a5868ae33c244d56887b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:17ea675257d2adb46b05323fd124289bb53158151c4ecea7bfec4b1e15bad9bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:b231dc8e1dc56badbb8b1763a37beb81b0b94ed17a15858b75ee4633d6099584
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:efa4573ecbc5d91843958f2b242cfc91bc12799a9e3885c88d0d2a50e548a0c9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:3cb5c1e5d2703d2a8f9c1e7222da4ecd9a4d8494210b907bb9cdbe66b5130abd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:284d0de0b84d0d1759949a748cd7d849cc7810391d2d75cc9a39a58167e7672c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:db275cb6a59925874b7d6b5c6e7ff16a7b1eec8ad43b121c42cf0863efdbbf38
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:acd09845c2981ccec3ecd994f54b237e5c7900fd4c2d8acb4cb0422f3787201e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:4751f4bd27adda5b2e5a101d7c8c9eb63b9216e66a1ac8b2287bfd5ac70a1920
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:d7206e070356b6be4d662013993facacb04fe42b16ba0bc514c905355ea1ab86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:3dba9275d52c39f3c479a0f646a626f78219ef98f54322d1e4c2bb15321b6fe1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:efd7f08c3f2e8f6e44cc8ed63eeff8fbd62421d4f68fd42b34f145aa941ea996