Sign inSign up
Tempo Query

dhi.io/tempo-query

Tempo Query 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.10-debian-fips-dev, 2.10-debian13-fips-dev, 2.10-fips-dev, 2.10.8-debian-fips-dev, 2.10.8-debian13-fips-dev, 2.10.8-fips-dev

Index digest:

sha256:d0f33fbfee58d3dbae4334e5f7d1b5acc20831ace934ae792c6a2678fb2616fb

Manifest digest:

sha256:dc330da62fdcc538a0eacc07e3f648d254d3aaf633d12b349955fa61ba7cfe5c

Size

36.30 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo-query:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo-query:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo-query@sha256:0144af7f66436dd3ecb7752dc16d1c5a4645e9c19d9194648934e36e7039b9ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo-query@sha256:a88493f95c5dcc323e3fc680826e89c747d3a31d9928d8246ed364070faf2154
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo-query@sha256:fbc5a9d65351c1e0a86a20624f5c5d62286377097a9ebf85c85388eae98b5569
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo-query@sha256:55a35ae9366934d6eb1e2f74c937eb6a8f673ba8af9d4703af5dc9748c0594b3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo-query@sha256:88288afef0709df8b30dbf0b410b6f72d2e7d808e973c46bf9061374e04e560f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo-query@sha256:09a121c98253f0fc0d7f6c78caf8f75b6aae26d6065da3359bfae2c47ea86120
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo-query@sha256:2a896cb0c13558a6563c5a823524eafc86ed2aa0489c0f199f50f40622fe3f04
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo-query@sha256:4cd1677534e283675dbe93e869320d1addc2e771cf309058a3866bdbbc111b8e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo-query@sha256:184bd28fea3dee7622f7fc398fe73ce5c0bc9d0d1c28f23472e72fe0c0585ca1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo-query@sha256:6acf10e5f644089c7ed8916279fad358a8d2754a11f9b5f9f1c1ed1ddc865d55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo-query@sha256:ea6a342dea032dfaf128a37906c57341395f8a8cf8b0ea6e9d38f1c5337f05b7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo-query@sha256:c9e079d650a53fc6d22c2db4fda15b6b615ba09efc1b177858cf49746fa8e701
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo-query@sha256:502630227cf00fa98f648aa07494fccd063d09d1df868216cb9206a18de8d48c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo-query@sha256:4a4f8d509fd2baa7ff08fe96c85f7b84deb0981cbb5bb38e1953494595b5a871
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo-query@sha256:5ffd4e73342ed4a0fd802de68086e4458f4097b264ba7a5a981d71dc5de11c81
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo-query@sha256:52ce0459da88877994e1872031a3c984b4dabfb73c7329a8d7c0ac8afcfd7e3f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo-query@sha256:7869ca27a795ea08fbf1fcb3d85e8e4d3721a51680fb0a7a2e4186ff40d1744d