Sign inSign up
Temporal Server

dhi.io/temporalio-server

Temporal Server 1.30.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.6-debian-fips, 1.30.6-debian13-fips, 1.30.6-fips

Index digest:

sha256:1b95b8eb552ab9558bf86cdc46f0c1e80e4cd7f4d26a67ef75cd5dad0b5acacb

Manifest digest:

sha256:1e2e7f7929fdd9ac731b575c9b30af1eadcc48388e1305883a89188d6d1850e1

Size

43.36 MB

Last pushed

7 hours ago

Vulnerabilities

1
2
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/temporalio-server:1.30-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/temporalio-server:1.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/temporalio-server@sha256:e52a9b57fe33cbb34a9954c7b1b29ef4569d6f45e0a105cc38b29e04b69b1d91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/temporalio-server@sha256:6bd5ec5cb1426405936400386789077e34f4c070ce8f5e6a75921659d3311ea0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/temporalio-server@sha256:ec25efedbdfbcd1b36f813ee4937ab21d66e62bf671b3527daa49e5d0408a849
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/temporalio-server@sha256:87b1ca0761de94c6b6a4678f702dbdeb967b2da85480707493b5731d4cb5637c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/temporalio-server@sha256:64a706c81821110b7f6168d75b9b7bf0b9e6b06bb99e5abaeda8679322df3bab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/temporalio-server@sha256:b12ea86408e3d2e129e49a46271da63e89341be3c5335546a2c6f69af8ce9afc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/temporalio-server@sha256:2108b9e12e045523d544d15b95670dff8ea91fb33336e152c588221911c29c07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/temporalio-server@sha256:a5f8a159972039487d841df2cc2732c9c5aa0ec66f79a5ae46b1d48ce146f367
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/temporalio-server@sha256:387bd5dee4d658e7d718857150561869411147c00f08bb2a3b1cf40cdf419e58
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/temporalio-server@sha256:9c2dca2518c99ddf70f3eda6852d66d0eacc72150ee016f0581ca6b15a7ed8b2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/temporalio-server@sha256:3e7b138abf0e70d18bef668932ed4b5cf236a5fa7093835b0f9fcb78925ade76
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/temporalio-server@sha256:d9ddccd9416e36ef65172ec43796e1fa58bfc4539f850949c36d9aaed6424bb9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/temporalio-server@sha256:68a33ca0a85c646a6fa8d8f36930a2954eccb2993942af3ae0255699cba160e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/temporalio-server@sha256:d7c8594e2afe7e244e34a4c5252e101e386b6ebc691d12a889ac2e43f95dc194
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/temporalio-server@sha256:cced8162eebc378aea539758b174c42eb40322f090b214d6ce1a7867f6784a7a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/temporalio-server@sha256:037bf0298a4ba3793a0977c2e8f94499cd430623344d4953f899e798c317c3c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/temporalio-server@sha256:99659d6352e097057ebfb7f76db2f70fbebbe23ccbb67339782d2387c08cbc39