Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.42-debian-dev, 0.42-debian13-dev, 0.42-dev, 0.42.4-debian-dev, 0.42.4-debian13-dev, 0.42.4-dev

Index digest:

sha256:37c966ecdab0bc114d97e9bbab0f1a7a2f392f28af0b6ea9611ae106fa4e6da7

Manifest digest:

sha256:7157d03453e513b2615c399c252c1621c4139cbd71d795719dc123acede2a024

Size

73.00 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:4327468ce732ffd862055fa8f62da36842d293571d016ff4758de71e374d26ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:b13ea39030011b5c84f4e7a3a62a5b371cf9e52613d751e6276a048eb7e365cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:969f5569af9166234da7318bb1de2c7f8c08b8e7de72fec4d696021f788d1976
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:da309f6286b9d9bcb03575ef41153cce05a227a05c7fe0f32ba8ccf9116b18bd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:145a61c6055b2515da9af68ce10df4a4f27c3a305fb54d4482fbe27089c97a3e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:1c485f266b6ed742cebb22419567c17f359ddc724bea1d3a0b3b5ae1ba65b169
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:3ba60d277fd7aa5f1a4f3fce6eae0b697e191d8c705bd3fb856958a65b5f0ce6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:eb0f224384f5a64546bd585687d19c122522bc097677112368578b06a55bf4e8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:ea857d9d84ce8de48902f0e58a96e4254eeb731837afe0c10bc2d192e54393c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:7d47f0f6e9334f5eb289bd164f1cbea09b18dfb7778144e9af50f446e958415d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:544f2365dfefec90b705011c0a5b1ebb75a7a325d09fa8248764c78f67daec01
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:74fc439c2fb0a153aee2815d51f3c6e4eba048a7b23bb9f443e3d3ed40635b82
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:9aad03808c8695d63c7e1ea54e9d4bdffd1e516e5c1e660f140cdd33af4129a7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:cf6ad1b8560c7a5400e82cfa01147f812b5f565515b77bd8cb6138da4d3a2f88
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:94f0a1eafe45619823182a19f2738fd0a92bf92a0e6823a45459d694ccd0e3c9