Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.42-debian-fips, 0.42-debian13-fips, 0.42-fips, 0.42.4-debian-fips, 0.42.4-debian13-fips, 0.42.4-fips

Index digest:

sha256:21da2a05cab5a01b03ea296668ead958272c8d4effd6fb836c7da3272ad188c1

Manifest digest:

sha256:a41e34d6e82e03bd20391d877be101de559e1864a774d7fcec00404524ff0059

Size

35.64 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:122a7c94d09a988d40ba83306dbcd09e79b34b9bc5f724031a77317f162ef5f3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:755ff89b7aa4669e608c5a39080bb2406a31f1f2b6f2f4ff141f7053e06bb692
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/thanos@sha256:5fbc4bf731572639ca92905c35cef325f8732f153c3b59ddd73c44e460ef2279
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:dc5f44a4113032afed8bf41716462dfa6545cb7b0c04f814d154936368731a5f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/thanos@sha256:2d4f6306a23e6f1b48b0ce552745c6bc5df57f4cc934ca4171d843d79e768371
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:b71bacfd76e0a6568cd0398dc4d1b88c5fc466bde6ed9c9095d523b2fa9837a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:b9599ca45747c7193b9f60d5796d98e56e5ddaf4f1bdea072e12477629d4b60e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:ea0ea48be36ad0d9c51ae14c17f7b7683ca59a614c5522f619c451d8239b747a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:f02ecf12057f17f5ca4ee8adc44f962b86f1929f08f09c65d7a0780c76dcfb91
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:1977edf21d07ed137585c399a57f660326b242482b49dd0396575151be7ad7fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:81fb3047a3dc8576342741679cbf7b91eaeb6389706a69ec9e8cbb4e3c048526
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:385d1e14dbeb77498ea0e75fc6a50de68988a080446d9d8198c7d2e474d21e21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:2c17819b83e128815f02cfe733dc1e9917a3672fd626c5f9f27eb3d7f52b7278
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:1cf13a913169cfb9936afa0ad72c470cefa951a7f55d889ecee8f7871e2e3ad5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:6191a635623a13ff2d6a6a51a7537ea2e59e903ec170fdcd5e3fa35dc8b450b6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:16fd89c9272097c8524e5104b0d17d199055ca9ca1c2f88ad05ff476bec0c8b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:8de1257abc8fac05630c63315e9e9522e84a562671336b9412e5a255405a0dd6