Sign inSign up
Grafana Tempo

dhi.io/tempo

Tempo 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.0-debian-fips, 3.0-debian13-fips, 3.0-fips, 3.0.3-debian-fips, 3.0.3-debian13-fips, 3.0.3-fips

Index digest:

sha256:5d2201f6d665e1e21cbf39aa98ff226e2cba0855b565b1c3ae33ecb95c19a742

Manifest digest:

sha256:ec86af28f3013e072d0ce13d7dd9bc7f30fd7e53ab4b02195e46e4bf0ecb991b

Size

40.06 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo@sha256:162bbb3b7d79287f1977916dceee0e747b327a454078528ce6ab2cc4d6d301f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo@sha256:52403b6edf331d8aa9cee5b24f24e7c4ac3049060bde20af63c4dffc0985205c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo@sha256:8d93bb1c0eac8e7fa1e4d953fbef515e0829bb20c78be0f8fde1cd19fdf09cb3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo@sha256:8d2815d29f6e886557ba23b5336ded18ae3aca4efd123ed8fe77d14648dbddcd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo@sha256:9f236272672e34eb9ca6d708b41304698ca733383a1d3f47b1d2d4b19d3ba5b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo@sha256:2a500a08a9f339ff8a7a6041fd06dc770aae9a3215662ff9c06bf18f79c0ec63
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo@sha256:f85971535f24382acc706672ded0edfac819bf89fa1318ddfc9cb576dc249a3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo@sha256:cbd5282f5449a03bbdd3723c35561667cb652a3e3a82d47c509d36b2ad9fd09d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo@sha256:ad168f84a05eab1350f76f881d93d88ac39fb8695e9595d7f876f7e6cfa0050c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo@sha256:4dbeeeeb0389c8e0815e0722c37047afca7f39fce6460f71b05339a73807c27b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo@sha256:f5773b66395860f7a8a5c52c0f4e8446c98794e3253e8e1e05038371393e59cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo@sha256:2b31575ec1d9f7b06acacb0db6aaa26d9617d009086da76cbb91e85b48b240b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo@sha256:d43577f765cabdafd66ac7e781c50937ce68329cd52996fa98c36c71017bfe3a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo@sha256:e3bfcf2704def7ad4aa84fce2667e2ded0e160a11b82b207fb56b298dd0f859a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo@sha256:192111bf439e994e59f90dfa68fd6962a06eeeb1305b64c78110beae8f5a9858
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo@sha256:ab6eae2b40f8ad05d7bfc83ff1534667fb2dc5126b5900d7d75352ac5c503941
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo@sha256:ba95fe65dab26b5beef77532cc6eb72393a59db03522573bb15d80372fc5a27f