dhi.io/tempo-query
3, 3-debian, 3-debian13, 3.0, 3.0-debian, 3.0-debian13, 3.0.3, 3.0.3-debian, 3.0.3-debian13
sha256:d2e4eb77ae7a7bf189cf5d4132d44eb1493b7d2bf4b45d0e1d48499ad9bae4ff
Manifest digest:sha256:5e0bc9e41bf47454513b56d49e5303518b7e58bc870f0389dd12c5f3fa1fe4cf
Size
6.94 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:32. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:3 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:c961b5465df7bb81af2f145443eecb87fc7b00b68b93b1bb626d91c5d33f8944 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:1f8b6a456e8b62237eeda736efc2e9250ebc536d5a8fa961746ff0834087772f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:39b1b55536223ba68ddcd41aff5b873ef92cd1c1b28a1caa44e8c9e9ebcff24f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:10deb3e8a526a7184cd96c025be105ac68feeb11a3464900c11eaaf5f787913f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:853d1eaf6d1c511fb3d374a850854c4eed717508bf785e5990daf071e674da9a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:1e652a75bb2092e49b9e74b80986b19c50f1c93455c93102d136c7d507d62cc1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:63a0557e607193fd4df6cdc5fc90361d5d954f69347a4284d0d7b4aeea113f6a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:657cc5ae393363489307de0a72e1bc02f8bfc829e790c624e7860522588a234d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:46569012ff8cad907c1f5ce0b8e11c2db26dd1f545a87310e4b4e522e0d5d214 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:f3abf1cdb42e100cb300bbd2f86bfd51148caacd1f624daa49f96c48f3669834 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:4c3b9e19fa602a6fa8d2320e294eef05ab166576e870d0af3c494caba53940af |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:bfe0a5cbf4412b22a28d4cf8c816d417016b1fe829dc59ed27a3b32cb8bf9926 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:b77f55ace2c94f7805defe625bfda651d43ff249ce45a684a5abe1ac7bca7171 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:a3446b9a096fabc9e5add9d756a72f9194fe0b5162a58dc943e712fba33ab559 |