Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.42-alpine, 0.42-alpine3.24, 0.42.4-alpine, 0.42.4-alpine3.24

Index digest:

sha256:f3c9cdc16bf765f3c7132226b14d36a0bd884d85b9891dba16bdc5176daab847

Manifest digest:

sha256:e428a6e61da8e399492aea54872b21ea2fbf5eeca819759002fddc7ca1818a16

Size

27.17 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:2c7bc1af75440ea55adfb95be00e0764df72c3bff60119e6267d997fac4a5b24
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:1c846c3e467fff28259cfb3e27327910a8e9b411e2af9c2677640afab4cad693
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:e7c8e2f0be339a918ca6159604d2076b6e75554537e180f312df95261aabd7a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:dfc655cd99694ae8e4e3f8c9a5c60098037860503be4d1ae6ab644069bad4e24
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:1b22b43e9fd1a150d0aae772078a12b672211fd6f6a4dafde47d686b7b6b2c55
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:8b3f0c7314bc7d946cc3c7648a60450f8478a095ed2296912614bfa415f45882
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:4589bad7a3899a6a5e1eb456ab339b73814673cc46744c63184b8cf30726577d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:7a515137e6d3d2d9de2a783292006a8216ca154226c54fa1504f340b464f3bed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:147ba6fc2bac81393a383a76c1d75fc2bae1fc8b8ca3bd0a8a2f092a9b0ae260
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:4af3385b2dd0456c24b0931505f2631a0cb051a6f0be926634d4dde691d5ef22
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:dee98c556bb2231abbd338c7bfe583d33218fbbccef4a418f4188f957a929ae4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:bdc86676b0ab0c5591d3f887c31e58ebf328021a68c7a35806bff681b9b7f1bd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:0da4714e6c2edf10e6491b0f35a1c56bc4cbb096a4e67f82151fa42f2bd56cfb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:b3a73f20bc6a9c4c7668549df98ca18bd9b8372b84fbbe2e0b26aaebad164bd0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:6dd9093272e18ddeb3a0f2e5ff98fccc6dfefdac749220473f3c93fbc7c6b774