dhi.io/tempo-query
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.10-debian-fips-dev, 2.10-debian13-fips-dev, 2.10-fips-dev, 2.10.8-debian-fips-dev, 2.10.8-debian13-fips-dev, 2.10.8-fips-dev
sha256:d0f33fbfee58d3dbae4334e5f7d1b5acc20831ace934ae792c6a2678fb2616fb
Manifest digest:sha256:dc330da62fdcc538a0eacc07e3f648d254d3aaf633d12b349955fa61ba7cfe5c
Size
36.30 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:0144af7f66436dd3ecb7752dc16d1c5a4645e9c19d9194648934e36e7039b9ac |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:a88493f95c5dcc323e3fc680826e89c747d3a31d9928d8246ed364070faf2154 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo-query@sha256:fbc5a9d65351c1e0a86a20624f5c5d62286377097a9ebf85c85388eae98b5569 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:55a35ae9366934d6eb1e2f74c937eb6a8f673ba8af9d4703af5dc9748c0594b3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo-query@sha256:88288afef0709df8b30dbf0b410b6f72d2e7d808e973c46bf9061374e04e560f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:09a121c98253f0fc0d7f6c78caf8f75b6aae26d6065da3359bfae2c47ea86120 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:2a896cb0c13558a6563c5a823524eafc86ed2aa0489c0f199f50f40622fe3f04 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:4cd1677534e283675dbe93e869320d1addc2e771cf309058a3866bdbbc111b8e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:184bd28fea3dee7622f7fc398fe73ce5c0bc9d0d1c28f23472e72fe0c0585ca1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:6acf10e5f644089c7ed8916279fad358a8d2754a11f9b5f9f1c1ed1ddc865d55 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:ea6a342dea032dfaf128a37906c57341395f8a8cf8b0ea6e9d38f1c5337f05b7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:c9e079d650a53fc6d22c2db4fda15b6b615ba09efc1b177858cf49746fa8e701 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:502630227cf00fa98f648aa07494fccd063d09d1df868216cb9206a18de8d48c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:4a4f8d509fd2baa7ff08fe96c85f7b84deb0981cbb5bb38e1953494595b5a871 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:5ffd4e73342ed4a0fd802de68086e4458f4097b264ba7a5a981d71dc5de11c81 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:52ce0459da88877994e1872031a3c984b4dabfb73c7329a8d7c0ac8afcfd7e3f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:7869ca27a795ea08fbf1fcb3d85e8e4d3721a51680fb0a7a2e4186ff40d1744d |