Nginx 1.26
hardened
Size Reduction
38%
196.1 MB to 120.7 MB (75.4 MB saved)
Component Reduction
87%
150 to 19 packages (131 removed)
Vulnerability Reduction
99%
117 to 1 vulnerabilities (116 eliminated)
Image Comparison
| Property | upstream | hardened |
|---|---|---|
| Image | docker.io/library/nginx:1.26.3 | ghcr.io/armorred/nginx:1.26-hardened |
| Size | 196.1 MB | 120.7 MB |
| Layers | 7 | 22 |
| Components | 150 | 19 |
| Vulnerabilities | 117 | 1 |
| Runtime User | root | 65534 |
Vulnerability Analysis
upstream
117 total
hardened
1 total
Upstream vulnerability details (117)
| CVE ID | Severity | Package | Version | Fixed In |
|---|---|---|---|---|
| DEBIAN-CVE-2011-3374 | low | apt | 2.6.1 | unfixed |
| DEBIAN-CVE-2022-3715 | high | bash | 5.2.15-2+b7 | 5.2-1 |
| DEBIAN-CVE-2016-2781 | medium | coreutils | 9.1-1 | 9.4-1 |
| DEBIAN-CVE-2017-18018 | medium | coreutils | 9.1-1 | unfixed |
| DEBIAN-CVE-2024-0684 | medium | coreutils | 9.1-1 | 9.5-1 |
| DEBIAN-CVE-2025-5278 | medium | coreutils | 9.1-1 | unfixed |
| DEBIAN-CVE-2021-22922 | medium | curl | 7.88.1-10+deb12u12 | 7.79.1-1 |
| DEBIAN-CVE-2021-22923 | medium | curl | 7.88.1-10+deb12u12 | 7.79.1-1 |
| DEBIAN-CVE-2022-42916 | high | curl | 7.88.1-10+deb12u12 | 7.86.0-1 |
| DEBIAN-CVE-2022-43551 | high | curl | 7.88.1-10+deb12u12 | 7.86.0-3 |
| DEBIAN-CVE-2023-23914 | critical | curl | 7.88.1-10+deb12u12 | 7.88.1-1 |
| DEBIAN-CVE-2023-23915 | medium | curl | 7.88.1-10+deb12u12 | 7.88.1-1 |
| DEBIAN-CVE-2023-28320 | medium | curl | 7.88.1-10+deb12u12 | 7.88.1-10 |
| DEBIAN-CVE-2023-38039 | high | curl | 7.88.1-10+deb12u12 | 7.88.1-10+deb12u3 |
| DEBIAN-CVE-2023-38545 | critical | curl | 7.88.1-10+deb12u12 | 7.74.0-1.3+deb11u10 |
| DEBIAN-CVE-2023-38546 | low | curl | 7.88.1-10+deb12u12 | 7.74.0-1.3+deb11u10 |
| DEBIAN-CVE-2023-46218 | medium | curl | 7.88.1-10+deb12u12 | 7.74.0-1.3+deb11u11 |
| DEBIAN-CVE-2023-46219 | medium | curl | 7.88.1-10+deb12u12 | 7.88.1-10+deb12u5 |
| DEBIAN-CVE-2024-0853 | medium | curl | 7.88.1-10+deb12u12 | 8.6.0-1 |
| DEBIAN-CVE-2024-11053 | low | curl | 7.88.1-10+deb12u12 | 7.88.1-10+deb12u10 |
| DEBIAN-CVE-2024-2004 | low | curl | 7.88.1-10+deb12u12 | 7.88.1-10+deb12u6 |
| DEBIAN-CVE-2024-2379 | medium | curl | 7.88.1-10+deb12u12 | 8.7.1-1 |
| DEBIAN-CVE-2024-2398 | high | curl | 7.88.1-10+deb12u12 | 7.74.0-1.3+deb11u12 |
| DEBIAN-CVE-2024-2466 | medium | curl | 7.88.1-10+deb12u12 | 8.7.1-1 |
| DEBIAN-CVE-2024-6197 | high | curl | 7.88.1-10+deb12u12 | 8.9.0-1 |
| DEBIAN-CVE-2024-6874 | medium | curl | 7.88.1-10+deb12u12 | 8.9.0-1 |
| DEBIAN-CVE-2024-7264 | medium | curl | 7.88.1-10+deb12u12 | 7.74.0-1.3+deb11u13 |
| DEBIAN-CVE-2024-8096 | medium | curl | 7.88.1-10+deb12u12 | 7.74.0-1.3+deb11u14 |
| DEBIAN-CVE-2024-9681 | medium | curl | 7.88.1-10+deb12u12 | 7.88.1-10+deb12u9 |
| DEBIAN-CVE-2025-0167 | low | curl | 7.88.1-10+deb12u12 | 7.88.1-10+deb12u11 |
| DEBIAN-CVE-2025-0665 | critical | curl | 7.88.1-10+deb12u12 | 8.12.0+git20250209.89ed161+ds-1 |
| DEBIAN-CVE-2025-0725 | high | curl | 7.88.1-10+deb12u12 | 8.12.0+git20250209.89ed161+ds-1 |
| DEBIAN-CVE-2025-10148 | medium | curl | 7.88.1-10+deb12u12 | 8.14.1-2+deb13u1 |
| DEBIAN-CVE-2025-10966 | medium | curl | 7.88.1-10+deb12u12 | 8.17.0~rc2-1 |
| DEBIAN-CVE-2025-11563 | unknown | curl | 7.88.1-10+deb12u12 | 8.14.1-2+deb13u2 |
| DEBIAN-CVE-2025-13034 | medium | curl | 7.88.1-10+deb12u12 | 8.18.0~rc2-1 |
| DEBIAN-CVE-2025-14017 | medium | curl | 7.88.1-10+deb12u12 | 8.18.0~rc2-1 |
| DEBIAN-CVE-2025-14524 | medium | curl | 7.88.1-10+deb12u12 | 8.18.0~rc2-1 |
| DEBIAN-CVE-2025-14819 | medium | curl | 7.88.1-10+deb12u12 | 8.18.0~rc3-1 |
| DEBIAN-CVE-2025-15079 | medium | curl | 7.88.1-10+deb12u12 | 8.18.0~rc3-1 |
| DEBIAN-CVE-2025-15224 | low | curl | 7.88.1-10+deb12u12 | 8.18.0-1 |
| DEBIAN-CVE-2025-4947 | medium | curl | 7.88.1-10+deb12u12 | 8.14.0-1 |
| DEBIAN-CVE-2025-5025 | medium | curl | 7.88.1-10+deb12u12 | 8.14.0-1 |
| DEBIAN-CVE-2025-5399 | high | curl | 7.88.1-10+deb12u12 | 8.14.1-1 |
| DEBIAN-CVE-2025-9086 | high | curl | 7.88.1-10+deb12u12 | 8.14.1-2+deb13u1 |
| DEBIAN-CVE-2025-6297 | high | dpkg | 1.21.22 | 1.22.21 |
| DEBIAN-CVE-2025-1390 | medium | libcap2 | 1:2.66-4 | 1:2.44-1+deb11u1 |
| DEBIAN-CVE-2018-6829 | high | libgcrypt20 | 1.10.1-3 | unfixed |
| DEBIAN-CVE-2021-33560 | high | libgcrypt20 | 1.10.1-3 | 1.9.4-2 |
| DEBIAN-CVE-2024-2236 | medium | libgcrypt20 | 1.10.1-3 | unfixed |
| DEBIAN-CVE-2024-12133 | medium | libtasn1-6 | 4.19.0-2+deb12u1 | 4.16.0-2+deb11u2 |
| DEBIAN-CVE-2025-13151 | high | libtasn1-6 | 4.19.0-2+deb12u1 | 4.21.0-2 |
| DSA-5949-1 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.14+dfsg-1.3~deb12u2 |
| DSA-5990-1 | unknown | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.14+dfsg-1.3~deb12u4 |
| DEBIAN-CVE-2022-2309 | high | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u5 |
| DEBIAN-CVE-2022-49043 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2023-39615 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2023-45322 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2024-25062 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2024-34459 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u8 |
| DEBIAN-CVE-2024-56171 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2025-24928 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2025-27113 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u6 |
| DEBIAN-CVE-2025-32414 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u7 |
| DEBIAN-CVE-2025-32415 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u7 |
| DEBIAN-CVE-2025-49794 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u8 |
| DEBIAN-CVE-2025-49796 | critical | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u8 |
| DEBIAN-CVE-2025-6021 | high | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u8 |
| DEBIAN-CVE-2025-6170 | low | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u8 |
| DEBIAN-CVE-2025-8732 | low | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | unfixed |
| DEBIAN-CVE-2025-9714 | medium | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | 2.9.10+dfsg-6.7+deb11u9 |
| DEBIAN-CVE-2026-0989 | low | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | unfixed |
| DEBIAN-CVE-2026-0990 | medium | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | unfixed |
| DEBIAN-CVE-2026-0992 | low | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | unfixed |
| DEBIAN-CVE-2026-1757 | medium | libxml2 | 2.9.14+dfsg-1.3~deb12u1 | unfixed |
| DEBIAN-CVE-2009-4487 | unknown | nginx | 1.26.3-1~bookworm | unfixed |
| DEBIAN-CVE-2013-0337 | unknown | nginx | 1.26.3-1~bookworm | unfixed |
| DEBIAN-CVE-2023-44487 | high | nginx | 1.26.3-1~bookworm | 1.8.2-2 |
| DEBIAN-CVE-2025-23419 | medium | nginx | 1.26.3-1~bookworm | 1.18.0-6.1+deb11u4 |
| DEBIAN-CVE-2025-53859 | medium | nginx | 1.26.3-1~bookworm | 1.22.1-9+deb12u3 |
| DEBIAN-CVE-2026-1642 | high | nginx | 1.26.3-1~bookworm | unfixed |
| DSA-6015-1 | high | openssl | 3.0.15-1~deb12u1 | 3.0.17-1~deb12u3 |
| DEBIAN-CVE-2023-6129 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.13-1~deb12u1 |
| DEBIAN-CVE-2023-6237 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.13-1~deb12u1 |
| DEBIAN-CVE-2024-0727 | medium | openssl | 3.0.15-1~deb12u1 | 1.1.1w-0+deb11u2 |
| DEBIAN-CVE-2024-12797 | medium | openssl | 3.0.15-1~deb12u1 | 3.4.1-1 |
| DEBIAN-CVE-2024-13176 | medium | openssl | 3.0.15-1~deb12u1 | 2025.02-8+deb13u1 |
| DEBIAN-CVE-2024-2511 | medium | openssl | 3.0.15-1~deb12u1 | 1.1.1w-0+deb11u2 |
| DEBIAN-CVE-2024-4603 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.14-1~deb12u1 |
| DEBIAN-CVE-2024-4741 | high | openssl | 3.0.15-1~deb12u1 | 1.1.1w-0+deb11u2 |
| DEBIAN-CVE-2024-5535 | critical | openssl | 3.0.15-1~deb12u1 | 1.1.1w-0+deb11u2 |
| DEBIAN-CVE-2024-6119 | high | openssl | 3.0.15-1~deb12u1 | 3.0.14-1~deb12u2 |
| DEBIAN-CVE-2024-9143 | medium | openssl | 3.0.15-1~deb12u1 | 1.1.1w-0+deb11u2 |
| DEBIAN-CVE-2025-11187 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.4-1~deb13u2 |
| DEBIAN-CVE-2025-15467 | critical | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2025-15468 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.4-1~deb13u2 |
| DEBIAN-CVE-2025-15469 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.4-1~deb13u2 |
| DEBIAN-CVE-2025-27587 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.0-1 |
| DEBIAN-CVE-2025-4575 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.0-2 |
| DEBIAN-CVE-2025-66199 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.4-1~deb13u2 |
| DEBIAN-CVE-2025-68160 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2025-69418 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2025-69419 | high | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2025-69420 | high | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2025-69421 | high | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2025-9230 | high | openssl | 3.0.15-1~deb12u1 | 1.1.1w-0+deb11u4 |
| DEBIAN-CVE-2025-9231 | medium | openssl | 3.0.15-1~deb12u1 | 3.5.1-1+deb13u1 |
| DEBIAN-CVE-2025-9232 | high | openssl | 3.0.15-1~deb12u1 | 3.0.17-1~deb12u3 |
| DEBIAN-CVE-2026-22795 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2026-22796 | medium | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DSA-6113-1 | unknown | openssl | 3.0.15-1~deb12u1 | 3.0.18-1~deb12u2 |
| DEBIAN-CVE-2005-2541 | unknown | tar | 1.34+dfsg-1.2+deb12u1 | unfixed |
| DEBIAN-CVE-2022-48303 | medium | tar | 1.34+dfsg-1.2+deb12u1 | 1.34+dfsg-1+deb11u1 |
| DEBIAN-CVE-2023-39804 | medium | tar | 1.34+dfsg-1.2+deb12u1 | 1.34+dfsg-1+deb11u1 |
| DEBIAN-CVE-2022-0563 | medium | util-linux | 2.38.1-5+deb12u3 | unfixed |
| DEBIAN-CVE-2024-28085 | low | util-linux | 2.38.1-5+deb12u3 | 2.36.1-8+deb11u2 |
| DEBIAN-CVE-2025-14104 | medium | util-linux | 2.38.1-5+deb12u3 | 2.41.3-1 |
Hardened vulnerability details (1)
| CVE ID | Severity | Package | Version | Fixed In |
|---|---|---|---|---|
| OSV-2021-777 | high | libxml2 | 2.13.8 | unfixed |
Software Bill of Materials
upstream components (150)
- adduser 3.134
- apt 2.6.1
- base-files 12.4+deb12u10
- base-passwd 3.6.1
- bash 5.2.15-2+b7
- bsdutils 1:2.38.1-5+deb12u3
- ca-certificates 20230311
- coreutils 9.1-1
- curl 7.88.1-10+deb12u12
- dash 0.5.12-2
- debconf 1.5.82
- debian-archive-keyring 2023.3+deb12u1
- debianutils 5.7-0.5~deb12u1
- diffutils 1:3.8-4
- dpkg 1.21.22
- e2fsprogs 1.47.0-2
- findutils 4.9.0-4
- fontconfig-config 2.14.1-4
- fonts-dejavu-core 2.37-6
- gcc-12-base 12.2.0-14
- gettext-base 0.21-12
- gpgv 2.2.40-1.1
- grep 3.8-5
- gzip 1.12-1
- hostname 3.23+nmu1
- init-system-helpers 1.65.2
- libabsl20220623 20220623.1-1
- libacl1 2.3.1-3
- libaom3 3.6.0-1+deb12u1
- libapt-pkg6.0 2.6.1
- libattr1 1:2.5.1-4
- libaudit-common 1:3.0.9-1
- libaudit1 1:3.0.9-1
- libavif15 0.11.1-1
- libblkid1 2.38.1-5+deb12u3
- libbrotli1 1.0.9-2+b6
- libbsd0 0.11.7-2
- libbz2-1.0 1.0.8-5+b1
- libc-bin 2.36-9+deb12u10
- libc6 2.36-9+deb12u10
- libcap-ng0 0.8.3-1+b3
- libcap2 1:2.66-4
- libcom-err2 1.47.0-2
- libcrypt1 1:4.4.33-2
- libcurl4 7.88.1-10+deb12u12
- libdav1d6 1.0.0-2+deb12u1
- libdb5.3 5.3.28+dfsg2-1
- libde265-0 1.0.11-1+deb12u2
- libdebconfclient0 0.270
- libdeflate0 1.14-1
- libedit2 3.1-20221030-2
- libexpat1 2.5.0-1+deb12u1
- libext2fs2 1.47.0-2
- libffi8 3.4.4-1
- libfontconfig1 2.14.1-4
- libfreetype6 2.12.1+dfsg-5+deb12u4
- libgav1-1 0.18.0-1+b1
- libgcc-s1 12.2.0-14
- libgcrypt20 1.10.1-3
- libgd3 2.3.3-9
- libgeoip1 1.6.12-10
- libgmp10 2:6.2.1+dfsg1-1.1
- libgnutls30 3.7.9-2+deb12u4
- libgpg-error0 1.46-1
- libgssapi-krb5-2 1.20.1-2+deb12u2
- libheif1 1.15.1-1+deb12u1
- libhogweed6 3.8.1-2
- libicu72 72.1-3
- libidn2-0 2.3.3-1+b1
- libintl 0.21
- libjbig0 2.1-6.1
- libjpeg62-turbo 1:2.1.5-2
- libk5crypto3 1.20.1-2+deb12u2
- libkeyutils1 1.6.3-2
- libkrb5-3 1.20.1-2+deb12u2
- libkrb5support0 1.20.1-2+deb12u2
- libldap-2.5-0 2.5.13+dfsg-5
- liblerc4 4.0.0+ds-2
- liblz4-1 1.9.4-1
- liblzma5 5.4.1-1
- libmd0 1.0.4-2
- libmount1 2.38.1-5+deb12u3
- libnettle8 3.8.1-2
- libnghttp2-14 1.52.0-1+deb12u2
- libnuma1 2.0.16-1
- libp11-kit0 0.24.1-2
- libpam-modules 1.5.2-6+deb12u1
- libpam-modules-bin 1.5.2-6+deb12u1
- libpam-runtime 1.5.2-6+deb12u1
- libpam0g 1.5.2-6+deb12u1
- libpcre2-8-0 10.42-1
- libpng16-16 1.6.39-2
- libpsl5 0.21.2-1
- librav1e0 0.5.1-6
- librtmp1 2.4+20151223.gitfa8646d.1-2+b2
- libsasl2-2 2.1.28+dfsg-10
- libsasl2-modules-db 2.1.28+dfsg-10
- libseccomp2 2.5.4-1+deb12u1
- libselinux1 3.4-1+b6
- libsemanage-common 3.4-1
- libsemanage2 3.4-1+b5
- libsepol2 3.4-2.1
- libsmartcols1 2.38.1-5+deb12u3
- libss2 1.47.0-2
- libssh2-1 1.10.0-3+b1
- libssl3 3.0.15-1~deb12u1
- libstdc++6 12.2.0-14
- libsvtav1enc1 1.4.1+dfsg-1
- libsystemd0 252.36-1~deb12u1
- libtasn1-6 4.19.0-2+deb12u1
- libtiff6 4.5.0-6+deb12u2
- libtinfo6 6.4-4
- libudev1 252.36-1~deb12u1
- libunistring2 1.0-2
- libuuid1 2.38.1-5+deb12u3
- libwebp7 1.2.4-0.2+deb12u1
- libx11-6 2:1.8.4-2+deb12u2
- libx11-data 2:1.8.4-2+deb12u2
- libx265-199 3.5-2+b1
- libxau6 1:1.0.9-1
- libxcb1 1.15-1
- libxdmcp6 1:1.1.2-3
- libxml2 2.9.14+dfsg-1.3~deb12u1
- libxpm4 1:3.5.12-1.1+deb12u1
- libxslt1.1 1.1.35-1+deb12u1
- libxxhash0 0.8.1-1
- libyuv0 0.0~git20230123.b2528b0-1
- libzstd1 1.5.4+dfsg2-5
- login 1:4.13+dfsg1-1+b1
- logsave 1.47.0-2
- mawk 1.3.4.20200120-3.1
- mount 2.38.1-5+deb12u3
- ncurses-base 6.4-4
- ncurses-bin 6.4-4
- nginx 1.26.3-1~bookworm
- nginx-module-geoip 1.26.3-2~bookworm
- nginx-module-image-filter 1.26.3-2~bookworm
- nginx-module-njs 1.26.3+0.8.9-1~bookworm
- nginx-module-xslt 1.26.3-2~bookworm
- openssl 3.0.15-1~deb12u1
- passwd 1:4.13+dfsg1-1+b1
- perl-base 5.36.0-7+deb12u1
- sed 4.9-1
- sysvinit-utils 3.06-4
- tar 1.34+dfsg-1.2+deb12u1
- tzdata 2025b-0+deb12u1
- usr-is-merged 37~deb12u1
- util-linux 2.38.1-5+deb12u3
- util-linux-extra 2.38.1-5+deb12u3
- zlib1g 1:1.2.13.dfsg-1
hardened components (19)
- acl 2.3.2
- attr 2.5.2
- coreutils 9.5
- gcc 13.3.0
- gcc 13.3.0
- glibc 2.40-66
- gmp-with-cxx 6.3.0
- libidn2 2.3.7
- libunistring 1.2
- libxcrypt 4.4.36
- libxml2 2.13.8
- libxslt 1.1.42
- nginx 1.26.3
- openssl 3.3.3
- pcre2 10.44
- perl 5.40.0
- xgcc 13.3.0
- zlib 1.3.1
- zlib-ng 2.2.2
Download SBOMs
Usage
$
podman pull ghcr.io/armorred/nginx:1.26
Verify Signature
$
cosign verify --key https://armorred.org/cosign.pub ghcr.io/armorred/nginx:1.26