dhi.io/telegraf
1-debian-fips, 1-debian13-fips, 1-fips, 1.40-debian-fips, 1.40-debian13-fips, 1.40-fips, 1.40.0-debian-fips, 1.40.0-debian13-fips, 1.40.0-fips
sha256:1f210b8eaa59c736b1ee059b060b38584fed5b58d88f3f634529f7dc1f329b27
Manifest digest:sha256:76b381d3edc4ee65a76dc10188209ef977a3f39c4132c311d7076bf45d5ae924
Size
82.58 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/telegraf:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/telegraf:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/telegraf@sha256:bd1e774d4e65f87415d20bd18c2b49cba29cf04678aa0f73979e47d5c2a67290 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/telegraf@sha256:de5b2ec06a3d197c4794ae734276f55c49c52b41d8c6937d8fa235a29ae1b8f6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/telegraf@sha256:9514f20bb69d38317fab5f560a416c9c6b10ef06d4e51bf73b131cbe63f9d551 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/telegraf@sha256:186a36d4cc04889a93f2808272c2bac27ce61764daa5602fb0652c50f7d5fa69 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/telegraf@sha256:405fedacfbe277bdd5e4d9eaa33341f8f77bfb362203d002e6df6136080c66a1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/telegraf@sha256:9bbffb4d2e2f2047716e290d3d582cfd5fe781a256a3046aea5fd0402ed3add7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/telegraf@sha256:44ac620914ac7237b3c8540094eb8af8287af816c09f19909f4dd9d324d1b383 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/telegraf@sha256:05f11f6b4198b8704638f443b50629b84fe78b0af241f101731422e4178400f7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/telegraf@sha256:5730e22a616a7268f89d656a6035af960ff11e30e7c907a470e1667f293debc7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/telegraf@sha256:53032953f46083b03fc3341bb8fe03e515d7c75b2f591992fb8aa46ff6aea5c0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/telegraf@sha256:181db01b150e6bb84266f802d6cefba71e9d0dd51a653803ca728f341902b45c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/telegraf@sha256:ce7bec8f2cff0ece5c3af69cebae7df4c0d79e16cc5e9a0568b1d1efc2307f4e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/telegraf@sha256:c3f5a944dba14371a925d28f709feed84c3353e3aa550a1c9cbd5874399d9dc8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/telegraf@sha256:73b90d7178916ddcff121806f0400c58ed8d5c0c6eadca39779229b7e575d725 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/telegraf@sha256:2ccd3d2d01b805750dbad645269820d17795b889ab1061e869e225d536db3d46 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/telegraf@sha256:1c83af173f22c2218e25a6e4ed36f6357bfd868a26c81d2d26448b559096940c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/telegraf@sha256:155a34402b15c0de20ea615d1b7b30ac38e5960c7a128be3c031da1cf3de6a17 |