dhi.io/tempo-query
2-debian-fips, 2-debian13-fips, 2-fips, 2.10-debian-fips, 2.10-debian13-fips, 2.10-fips, 2.10.8-debian-fips, 2.10.8-debian13-fips, 2.10.8-fips
sha256:1e2bfdfc68baa02706c337916912860576b5025b2631b3b293aafa667db335d6
Manifest digest:sha256:ce67ff12626c49fd1898b56853f3e2d96ec0dbd61169953e7c2e1ad37b57f369
Size
15.15 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:e95d6752b0d0bace58a92320e83d80493d1a18490e4e63d67d64922418d8a1e1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:541d709e7e8c22e1e54c22ff0433db7d0aa50d7bb0df192bf3bbe0a6ab0e9a88 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo-query@sha256:6317bb8fc508b55f6884c9c7c8a68def9f88c712eba9c3255a78f9c32972f15f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:909af01ebe56ee96b2e42f540758f997fde4aae1a453fd313c676b44bfe33b42 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo-query@sha256:6cebcd118d21bfe9fae3c6b165a04d95229f57ff37069d56cad7a0541d9eb44b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:bdf0119aa08b2a96287466156a4b61d553bdbfe318e00fdd72aba6fdc6b22111 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:ef511ff856990f10b98a5bd0dcbc6e351a935caa9a82a14c255dcd7e0900f886 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:3bf692f7bade63659ffb68a7842710c4dda2c2b20b3bc696092b6fe4e489cd10 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:0fd30031c9670e1fd3282715a0e8dfa0d7b5ede079ba5f6f410784b0678877f9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:6bafe78a6373d2ccb540ddea758c0c32d5719725a6fd8cf3a74bd1e841c4eed9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:42aad5395e8a16b65d019c52e560b34575673af59c45d7ae2b1c0cafcd0324ec |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:46d9edd3f45da96ad7449b015de26f6eec80304645dfd8e970e44ba8f72192e8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:a5284ce8152908a49ee59d3ac8c3644cc2a6a38d5f40044439de2a1e7b883aad |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:a6fc91ae6fc41d92c04e096f54ab5fdae1e72bda7901dbc965ef5d721e666adf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:ad67cbdefc541da4780df8557ba3eaa4d0916385ebc0d0fce25d16996f2b55f0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:03cd16b82edbc9d7ca66b3d90646a408f7aafae5f408077af86fb05d89af2339 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:283641e01c7a3d4f7f048fb5f7b122befe57dfc2a68356c4eaa102dd9ffde447 |