Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 2.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.3-debian-fips, 2.3-debian13-fips, 2.3-fips, 2.3.1-debian-fips, 2.3.1-debian13-fips, 2.3.1-fips

Index digest:

sha256:2bde0540dd62a4b701cb67247ecb08a56df1545255b5e4aacc7c27d1ae97c987

Manifest digest:

sha256:68965d406b6af557c6a4f567446746c982594d74cb085aefaf065341098eab17

Size

59.73 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:b5477084d0a5a82da116bf5cbbbcc55b4009671e0e629e3e05818d0e0977ab84
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:2a6b02d6d22c67af606c1918747da4a517d4d9bc85c802fdfd5016b06fb440cc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:983943c7699a23cc6512b3b438ef808191b4e8e74de3bf8effd207f59ff5ec11
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:d84d724658a100368141cf4bcb5d3894dc90877c338f2cdada08398ab02d6e46
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:4eaf2c0ad8469887383efc60fd30981e45eb7e81825666e142659205fd45d647
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:0f305c468f2f03f1154d3cd47534ad615e0815f652534fe2347c693e6f189eb4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:6f81d6935ff24a0d98b0e9d3d4623b3a4bd55a77274c598eda271b7a851bbafc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:99cd3718ebe224dfdeb0a37a1e5ff37926eff3afe82a381b5f763613ebf70713
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:9a1efcce6c5ae330794a3ea8f230f4719cc02fab6d8e074d9e0cebb34fca5784
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:fddbe4d2eebb4e11acc1197c0efd84301392861ed83bb6a44c989c77426aecc8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:0604544b9910e83944add3c229cbe3e9377538f448c981524c0169a2489e45ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:c6c3c49c453b0abfc677c1ef9677ab7d45c844eaead98867e02d80eef36fbc30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:58e9f0146120fac3bf2e9350bf8a92fc38d0b2d8d0b9afbc78e3ca764e03374b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:787e366de8c2936473f0294f19a452513ef08dc51bbf4d6663912561da06db9a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:8313324d03972f310a4d85b447dbe24ada5c836a9c7a1bb6d5dc276095c64f22
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:f4e663f2e323df8566eda1093bfa385389039483001f101f6d6d09aa9c36ded8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:1d2519ae86509f70188da4888f0426f6066bcb2bbdf753904f9bd96f80a4bbc1