Sign inSign up
Tempo Query

dhi.io/tempo-query

Tempo Query 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.10-debian-fips, 2.10-debian13-fips, 2.10-fips, 2.10.8-debian-fips, 2.10.8-debian13-fips, 2.10.8-fips

Index digest:

sha256:1e2bfdfc68baa02706c337916912860576b5025b2631b3b293aafa667db335d6

Manifest digest:

sha256:ce67ff12626c49fd1898b56853f3e2d96ec0dbd61169953e7c2e1ad37b57f369

Size

15.15 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo-query:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo-query:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo-query@sha256:e95d6752b0d0bace58a92320e83d80493d1a18490e4e63d67d64922418d8a1e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo-query@sha256:541d709e7e8c22e1e54c22ff0433db7d0aa50d7bb0df192bf3bbe0a6ab0e9a88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo-query@sha256:6317bb8fc508b55f6884c9c7c8a68def9f88c712eba9c3255a78f9c32972f15f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo-query@sha256:909af01ebe56ee96b2e42f540758f997fde4aae1a453fd313c676b44bfe33b42
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo-query@sha256:6cebcd118d21bfe9fae3c6b165a04d95229f57ff37069d56cad7a0541d9eb44b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo-query@sha256:bdf0119aa08b2a96287466156a4b61d553bdbfe318e00fdd72aba6fdc6b22111
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo-query@sha256:ef511ff856990f10b98a5bd0dcbc6e351a935caa9a82a14c255dcd7e0900f886
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo-query@sha256:3bf692f7bade63659ffb68a7842710c4dda2c2b20b3bc696092b6fe4e489cd10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo-query@sha256:0fd30031c9670e1fd3282715a0e8dfa0d7b5ede079ba5f6f410784b0678877f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo-query@sha256:6bafe78a6373d2ccb540ddea758c0c32d5719725a6fd8cf3a74bd1e841c4eed9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo-query@sha256:42aad5395e8a16b65d019c52e560b34575673af59c45d7ae2b1c0cafcd0324ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo-query@sha256:46d9edd3f45da96ad7449b015de26f6eec80304645dfd8e970e44ba8f72192e8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo-query@sha256:a5284ce8152908a49ee59d3ac8c3644cc2a6a38d5f40044439de2a1e7b883aad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo-query@sha256:a6fc91ae6fc41d92c04e096f54ab5fdae1e72bda7901dbc965ef5d721e666adf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo-query@sha256:ad67cbdefc541da4780df8557ba3eaa4d0916385ebc0d0fce25d16996f2b55f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo-query@sha256:03cd16b82edbc9d7ca66b3d90646a408f7aafae5f408077af86fb05d89af2339
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo-query@sha256:283641e01c7a3d4f7f048fb5f7b122befe57dfc2a68356c4eaa102dd9ffde447