Sign inSign up
Tempo Query

dhi.io/tempo-query

Tempo Query 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.10-debian-dev, 2.10-debian13-dev, 2.10-dev, 2.10.8-debian-dev, 2.10.8-debian13-dev, 2.10.8-dev

Index digest:

sha256:cb0f411cffe72d0f6d603b8e163cb2e8dc0d62e91a2a37c2bf0fbe52c1185981

Manifest digest:

sha256:8d30f2bbde66b87b131e508a68aa0bc7ecf56f78f0855cadb28d1e1afa033373

Size

35.54 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo-query:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo-query:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo-query@sha256:ed03e021f951658c1950977706a22949d28de664c57be2f69149027e6afa61cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo-query@sha256:c4a1be4365f4a024c8a92a41ec64e53282b26f1c0ca99dd5ca50344630bd8243
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo-query@sha256:68328852ffc68a750dc6e34306279130e4d1e3f31a98780d55b9ed60b40a7da8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo-query@sha256:5d3c395f6a7925299f52a24f2103cc7b07ee584c23fbd8d55bd288a429e824b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo-query@sha256:a45bd2b34a12648010b8f8a1e4e013e99682d6df06747374de67f3a0fd41a2bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo-query@sha256:43883a572d7ea76aff3e485e8c638f1ff45e988aae4f721ea860d75d6140f03e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo-query@sha256:b8f631552b0f6fb6ef9c7684f63dc3c988ef1177f696814584b899cc09e0cf8c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo-query@sha256:f6a3d8f815a37053eec907991d8bd2d029d7b0fa063f9dd59f8d1cd623cf516d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo-query@sha256:d0f47a19b7b47dcf536236ed711a695f5ddb7037155f022b2d465f65f82b2435
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo-query@sha256:30ab0ea0f48690fe80003d8071bef5bf7feddecaa3efa086eb0fb4c6e0f250ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo-query@sha256:535e0aa60caac58446ec6893b3b1fcfce3cb19678d2f21d135af1730d4a3f41a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo-query@sha256:32fb0f9784f92e7110d8060b621d53d166f72dabdc04a0efd481ef852b5eb41d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo-query@sha256:f72355a3c5a2fbc09b98e14c0c6c5fef5f6bc6ef4c6154ff334d12139c99b222
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo-query@sha256:76760a06b6284e926dbc70bf6043693df52f074d25eaf68ca02195c1667b0a4d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo-query@sha256:1296a548a23734de602917063f9ca9de8be270dc5879dbb0cd7c5b6ded62ddaf