Sign inSign up
OpenTelemetry Collector

dhi.io/opentelemetry-collector

opentelemetry-collector 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.160-debian-fips-dev, 0.160-debian13-fips-dev, 0.160-fips-dev, 0.160.0-debian-fips-dev, 0.160.0-debian13-fips-dev, 0.160.0-fips-dev

Index digest:

sha256:2a54fbcb7f4f22d75df19d78b2892464f7d1d6fb0047bc253ad87b99628f3763

Manifest digest:

sha256:34ad9ceab7bf2c3ff776a6941dab7a437107c064988db77805c7a7eb1ab620e5

Size

86.33 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-collector:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-collector:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-collector@sha256:16d90828088303e34993691237e87e9b1c70d7697239727f49d5858d666de43c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-collector@sha256:e32b39b4cea546ac77573292ca7a395dfa0cd4cf2fd8cfc26fdca99d09df9294
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opentelemetry-collector@sha256:62c0962abdda917d7a1182dd13f553d8b5045a003d43d1605e2a80c1d5d39631
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-collector@sha256:620293d187f9a9eb03d00dbdf73588f723147e47e7faf31d4a528957155109f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opentelemetry-collector@sha256:5e9f6ea2dd485bfc0cb9b49a246c820cfd413e2654850761d01f96f1fde53623
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-collector@sha256:80ad41ccd2f2b4e2dba99a13d7753c5e8c4c29feea832fda956d775b719f1b26
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opentelemetry-collector@sha256:12656ee602658fcb1d8315ffb7dc8b2dd86b3eef5ccf65fff57f3f7166630d84
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-collector@sha256:5498f8ef46c588019fd57eaf3135155cb092d0e67db043188ad3f11a04b90f83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-collector@sha256:47f94baebf6ed26702de6f46a7233e77aae662fceb84f448250e8a9fe2c7a207
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-collector@sha256:5e84205236b1e37740c61c23b86142d30a3de739f7ef457a953886f783f3d9e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-collector@sha256:bb6e428c837b352f5aaa17e44987c6f6a08a854752c6e11c43de42fb4240ca14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-collector@sha256:600875bb50761895a6efb35e9dff71f91c376129ff291e5332865e87cfdfdb56
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-collector@sha256:ebe6ec9ef1ff777e19dbf0225979fe4c1ff9baa6020f41d913a2b6e5d4d287f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-collector@sha256:0a2f7e1336032be1797c25377cf7f4b5f22f0bd4dfcdac290df7bda6000bba89
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-collector@sha256:08268ed66bdfe3c2715cfc53823d3c84657ac9a53f864c0f1f942be3f2b30c59
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-collector@sha256:9bd30d4c39ee345b67dd5e2e14135ff5c7aeadf6f550b52ee88a32566d05aa5c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-collector@sha256:cb6814a58f4061f9c9dafdd904d62a39d0c95549308c258747683afdc40e6635