Sign inSign up
Grafana Tempo

dhi.io/tempo

Tempo 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.0, 3.0-debian, 3.0-debian13, 3.0.3, 3.0.3-debian, 3.0.3-debian13

Index digest:

sha256:342125e9ebfbce57d30aa5c027b98714e99f36bca4b7871f3ff8a56bf380bef3

Manifest digest:

sha256:798836869231edf0d9a0dd9c9693629c644de4e9422d3d756fe3e6fa9efc28e5

Size

32.15 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo@sha256:3d04822a965ff97fe94492ef224dc753a2155fcd681ab4d6df888313192d1221
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo@sha256:477caaad4e210582cef93e576f6784a6fdc25ad7283ff333cc4f4d2b49a99a46
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo@sha256:60926ed9a5b55835f95e176e05cb7c6256f19e19cff874dc4251d6a1665fc002
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo@sha256:6d4451f999df6324518656e2a5a6306e2a6788402ab86cb59e7fbac474b4b07f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo@sha256:993ba22c22a9303cac28dae658065cf6dca7985f37d83c22229ef3ee49426cf2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo@sha256:4411ea617b0103dc0d4aa9d32781c2a6cffa04afba03844ad8d9fc4c1b0b4ea3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo@sha256:6008c4ad39fe869d14bc4cd9d95c782c2bfb5a46d5f9ad4cfb6c9e49276cd01b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo@sha256:43561c9bf31da91ea541515c896e79116e071a87de105724198be3b7d1a53d79
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo@sha256:431902cf4141e275dffd8d04e6c55107bcce4d168b4f182774152ce43f42f63d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo@sha256:e35ada57f5307c6ccce3f02166b0b174f460fffa49acbbe52e037669d5f98808
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo@sha256:46950d932fc32c23eb9431470f6bf2e3ba299d1ac776b31843610417f33dab2d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo@sha256:64fdc82d70f5b118e9b99cfea809ea32652e4ad77f5fc553971272495651552e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo@sha256:640124b4c5f7bf22afe72994426eb1bca00fb1d1c68a8a67267447092c9346f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo@sha256:ed0c6bc4e2ab6fd2486013719c7c2c55f2969fc8dde0f38fa09524bafb446813
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo@sha256:3272de4b0c9f979a192fed1b05e884b5e7560b6383279b43faf384a878479830