Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.42-debian-fips, 0.42-debian13-fips, 0.42-fips, 0.42.4-debian-fips, 0.42.4-debian13-fips, 0.42.4-fips

Index digest:

sha256:48fd9a7ecb128c973961c22cf505c2eaf5c0ac297e877c585dbf422109c31486

Manifest digest:

sha256:5f05894dc541e2033b85fe73ab288db9bb62598ccb8bdada7e3e243449854fd9

Size

35.65 MB

Last pushed

50 minutes ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:f6d27ed728cd4b3d03a58a7059088f79ff14bf55e56d1da8bd4aafcf47281831
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:877d4a8511abd83043493e18862f85dd4d9cb9a049cb9ab96dc268c75f8714b5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/thanos@sha256:2077b1e1550534792199b83f178b60db9f91cec82e6c5ec4eecf6f4c3efc89fa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:e98b05eff5540b8519e733b77d4ce5a944cf5064bfda92fa322c9019c647e06a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/thanos@sha256:0823aa36898612ee2e49cf9ef0fe3d6f00c799e61b85708b7bccf2b8df9a4d20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:5a40d871a0ddec7b99d6cb98101e9ab981ba31e0ad212eb35e2989daac2a6393
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:35abef6e86ab8559852716421f1095b2aad34bc6b25de4aa1217dae60390d502
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:a263e73fc86bdd2e560c647b3abd7ccf68a55140b51cda83c86426823df537b7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:f63a146ae6e03d79beff9b7f8330b131d4891dd836e06f906711e47962865873
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:d12d961d40f91ce383178cff7b8ad19879fcedb21c5a1fc1a78cb8c97b54551d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:79cec05eabac0f19cc713dbbf419b3ed14a12bfcf56dc7fecd5c3dd6ca8433ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:6a42c73393dfb27490dbb6c8dac9353d02314895e0ff524986fb80a0a7d62f50
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:2f6de883e8f900a42342d350282af3ddd11c00899355c9639027615aabff6ef1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:2280b84b546443a77859d7d936d4e478c2da60921dfdb696ca8683c0b03ead74
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:8e8865b2785e1063e4f6ae99415482d64b492c59310752a78ed94c7b69270bc5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:0b1d7c8fcfc9b575e28cc6da30b695707886f5f4a660d8890532a913f7a59bcd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:b68b367ae4f23334331946d5f118515ccbb794f65b1d09e4740ee3e084a2daf7