dhi.io/tempo-query
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.0-debian-fips-dev, 3.0-debian13-fips-dev, 3.0-fips-dev, 3.0.3-debian-fips-dev, 3.0.3-debian13-fips-dev, 3.0.3-fips-dev
sha256:693bb3a2db70ba777e7209ed977f03f0089fdc6b9e324319d3d1f0947224fc93
Manifest digest:sha256:f61c6a9025046d4d443c71f4eb288a1d741974bcce6879c0c57a0a517e2fe37b
Size
36.26 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:b09b5e9c5376569c36e0b9f95469dd2476d2cada69ca12d4afcafe1e3d50284f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:1c44321b49f8521ce10f296e82ff7d891f9bc39a500928ffd885a6aa65631b99 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo-query@sha256:9930b7e91249b1c126f9a48667d28bfb435cecbd69c29520e4565b8814b7f2c0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:f8a9ead211bc43b0530bf1a79bf7405613704041902309cfabfc26e25c34aebd |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo-query@sha256:87ccadf156e1234031e4f8f14990d644ba9f9d68b8348accd3974fba900a7b9f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:f374a5a3213d11c22a1b308c6f32b0b3c0db7746e0a3a91588b8aa67b6d78b0a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:6e51e80632b123412ba3ea4e6ed333ef0924bd31846e9135d6faa6501a9dd28a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:4a304d1b573a6eda2d5f3a6dbd559752e4d37f331e4886e125ecb4e66b0cf0dc |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:c1e2bac0f2dd2a00378890c5c0b6de425b6108343b55d49421c2d8585aa7d141 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:e5e846e3c6be77f5bbc6dec5c9e6fbdf8ace7266e267e9ef4b201dbe793b9a35 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:d7c7de15fad7c66f66bfbd9f2cd7145117413655c64c9524fd4582b9cb5c3748 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:d466ed51dd8ac08ffadff947ae543f438b9576a20e984a9bfb57df9dcd26f49b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:84b24138b42ca00fc00ecc2f06c72d654b11ac785aa6b99caaade202c8a9111b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:132dc1a9224a92f1cf5188608c28b12915296dd0b76dd8ac93b5b9ac650234de |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:1d938a5734c37b4b06e8888b8fb436d719fcd04ad296c7a57596dcdb610dc0e7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:8db3aabc6c16b55891e8d3e4c2f6c596a33dd98f7e54be812c9e8496101c6fe0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:47e3959d0a5e2e77dce01208e0dba7991860895d87803cb4e9c4f4ec62bf2c46 |