Sign inSign up
OpenTelemetry Collector

dhi.io/opentelemetry-collector

opentelemetry-collector 0.x (contrib, dev)

CIS
linux/amd64
debian 13
Tags:

0-contrib-dev, 0-debian-contrib-dev, 0-debian13-contrib-dev, 0.162-contrib-dev, 0.162-debian-contrib-dev, 0.162-debian13-contrib-dev, 0.162.0-contrib-dev, 0.162.0-debian-contrib-dev, 0.162.0-debian13-contrib-dev

Index digest:

sha256:72e2f519877d26471695fe48625dcd1a7503cb60c6b4809bac773cc38e086692

Manifest digest:

sha256:60546156fdcc99fcfb563e1550396af5691318901af623fc2eac1bfc41fa592f

Size

204.13 MB

Last pushed

15 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-collector:0-contrib-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-collector:0-contrib-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-collector@sha256:787a6e05e86d20cbef728450cdb066ff46db94b61447261e1b42522120d7f2df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-collector@sha256:a89b702c5002668a69c3b7cb427d9fa3021bd70e6c099100a06b262acae69214
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-collector@sha256:ce2d19bf5e0d9619240678d5ebbe7d3bcce9387f7a8a64af69b79be08ee5bc30
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-collector@sha256:93b623609ac6b4a9714cb576e2981c499641a1a11be5aeadc485ea105e3f0c44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opentelemetry-collector@sha256:a66022e6857bfda6153ee6d07930e16975e102be0aa65a338da417c326b3c422
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-collector@sha256:775205709a411eb8b98f746245da0d4398cb2d2da44c214e2898efa691d504d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-collector@sha256:cf660e966fd5769237efe56d70da44a61c9a3f9939e83e6770fe08b314155c28
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-collector@sha256:b95a032cdb6552f62248b4d8597569d06645c5be0c3a90f7a6536cda4db8dab0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-collector@sha256:f1d434c38be0f94938e789f2c12043a7dd863bbe0aca8ce31fd179b29bd129b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-collector@sha256:b2f1f08b5940c1e8711cc74e9a07d3e8e118a9e940a41458559fd44ea5fd6e7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-collector@sha256:7cef325783872de3f3d2b8effe013d0b58099a9a7a4358b93b26ad75910d0667
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-collector@sha256:297873c364db8c9001c89b5359561fa6a4b0b8d3c37d1d2cd0af0e11d5be8805
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-collector@sha256:55357bd67a44079222e8642960a69fd3644b5eae2f184f108e06a10ebcd86fa2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-collector@sha256:6b5c4137c5480f5cbce354cdd70aa2181f1c714a392e8f38659776609feac8f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-collector@sha256:0dedd1be1005fc50920813706fd734223fc9e08fc81492c046397b39ddd0b24b