dhi.io/tempo-query
2-debian-dev, 2-debian13-dev, 2-dev, 2.10-debian-dev, 2.10-debian13-dev, 2.10-dev, 2.10.8-debian-dev, 2.10.8-debian13-dev, 2.10.8-dev
sha256:cb0f411cffe72d0f6d603b8e163cb2e8dc0d62e91a2a37c2bf0fbe52c1185981
Manifest digest:sha256:8d30f2bbde66b87b131e508a68aa0bc7ecf56f78f0855cadb28d1e1afa033373
Size
35.54 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:ed03e021f951658c1950977706a22949d28de664c57be2f69149027e6afa61cf |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:c4a1be4365f4a024c8a92a41ec64e53282b26f1c0ca99dd5ca50344630bd8243 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:68328852ffc68a750dc6e34306279130e4d1e3f31a98780d55b9ed60b40a7da8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:5d3c395f6a7925299f52a24f2103cc7b07ee584c23fbd8d55bd288a429e824b5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:a45bd2b34a12648010b8f8a1e4e013e99682d6df06747374de67f3a0fd41a2bd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:43883a572d7ea76aff3e485e8c638f1ff45e988aae4f721ea860d75d6140f03e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:b8f631552b0f6fb6ef9c7684f63dc3c988ef1177f696814584b899cc09e0cf8c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:f6a3d8f815a37053eec907991d8bd2d029d7b0fa063f9dd59f8d1cd623cf516d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:d0f47a19b7b47dcf536236ed711a695f5ddb7037155f022b2d465f65f82b2435 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:30ab0ea0f48690fe80003d8071bef5bf7feddecaa3efa086eb0fb4c6e0f250ba |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:535e0aa60caac58446ec6893b3b1fcfce3cb19678d2f21d135af1730d4a3f41a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:32fb0f9784f92e7110d8060b621d53d166f72dabdc04a0efd481ef852b5eb41d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:f72355a3c5a2fbc09b98e14c0c6c5fef5f6bc6ef4c6154ff334d12139c99b222 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:76760a06b6284e926dbc70bf6043693df52f074d25eaf68ca02195c1667b0a4d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:1296a548a23734de602917063f9ca9de8be270dc5879dbb0cd7c5b6ded62ddaf |