Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.42-alpine-dev, 0.42-alpine3.24-dev, 0.42.4-alpine-dev, 0.42.4-alpine3.24-dev

Index digest:

sha256:0d3c904bb33eb52b84cb99c61f55102403db4ae62edc840ddea0d901120938ee

Manifest digest:

sha256:c98fbda85cfef3c350db4940edd10aae376f058ede589fd2b9d026432d4d0250

Size

53.62 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:5c23fe20639f898c116198711d4ce63262c78634ca9aee1d3b4bd06ae74f41b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:acc4528c719094e5c5dbf3e55135ae067db3b833e050c52c5da8760c4048e1d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:efdde88bb738b408557ef12d5eaaa8997dfd38862aa20b5804bc7dbd1addd321
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:39863ec1609713fd6ce13304f961f66a0c7cba8fad281c3fa01340449b5ce99e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:88458dbd3725b5ae8eb7ae25d13fab8c6b642270747883f970f449726ef88b2a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:e92644a86792d5158daf192725e4318edb4d4bafc50fe108e5fb441156d3a320
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:6de86c3b0cf030e31c5be8ebb3f7dff06a5e82e571a3e2b5506c71cd3338976a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:eb91fecba1b521c161e3cc0b26c9cb38dd740a12aa283a5735699e79f65162f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:1b27da72cf4356676a1fda314d465e8f4a25f7f75b1839399da22e2606d5f458
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:a46184f51d67d10bf4f596d32e79d98609de2efbe3e48efb0e9c5be085821bb5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:516063011f42ddb6d3f78cb6697de6a26956dd994ef9b228e1401bfbcf48823e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:912049eaebf287c425f2f79406ef862fae06061922e12070ec01305118a9f428
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:32bc21d11b2ec21418fc72df78738836c927e11592af38cdf51b27632bea27b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:7cfb4bb53cf08a7ea7042e3d7ad03d5983512d6e6b5b441d0f4cb7b22b256a23
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:6811181567ca98214ddba77d9b5ef178b58967a1013082e4c5a93ca493085732