dhi.io/tempo-query
3-debian-fips, 3-debian13-fips, 3-fips, 3.0-debian-fips, 3.0-debian13-fips, 3.0-fips, 3.0.3-debian-fips, 3.0.3-debian13-fips, 3.0.3-fips
sha256:545888c56593b39b3f3ac71eebb19120c166fe670e2e2c79b05448907f1a0edd
Manifest digest:sha256:309b5f60fafafd06e6fb3e1f62d07aa8540652b822baab2aaf06dde140cca1bf
Size
15.12 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:0174b8b0d7b8ed07de3e9e5bb9f4e59d4cce17958a58ea6767fe9f2bae38b23f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:85c7bab7dc91c7a3df627924419973b2611e5faac33f496b7b8618e85f3ffbc4 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo-query@sha256:f59f44ab153f02cbdf5f4d63fb4101afbc88cc58d9ec542cd924f16c462f78d8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:0098f79c78c54f61b31a3214869d813e446d639b8fc0977cdb5b82d823f0263e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo-query@sha256:6f3ce579d44918a9928d43678e2080e38c034f79bb4cd96ecb813a682c0a46be |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:d9257f96f38bd7a780594193e81ddc6642e14e92cb2dc66f070cf2eb3bf97cb1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:5fca49b051c628ebe00bfc77d3d49c3720ef92ffe349c58b84324d3cad4d177e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:30c250790d46e0f3a4d321fe1c0e7d8bf1155120920a5f3e9849b7507579ee57 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:9e5cc6191ef41b26908fde8119174567b3ae6956e8ea7177764fdffc5c8db6b9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:82f435400988bfc99f5eacb9c0ebddbda7af487adc02cbcc6f877509b0ce1ecf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:103d655546377e65d4d8995a0f5d4d79177f01d7eb4b99d101cc09ad42f5d5bb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:1d104ede7f3c4e02d97dbf323be007a94544007e1357c25ee3fd8c96ac2086f8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:bd5c8cb7cd58f14dc6275399285c2d188572c109ee34604960245e2dbd012102 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:ff0760c2a55c23572d3c0ad5ced700b1f729011172d6e323657674881f12fc72 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:694645b63679430c7e8c4c77df2beae8b847e1ac4d628f475926f83b6a31a2c0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:9d95e02e99d7103a3d2b09b32d8a6385d9ac14a9f243f870cf77c9c0f98c88d0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:7d4dee8ab89d3a19cbe4db1b907f67de0996058a42e53536588af9450e30331e |