Sign inSign up
Prometheus Operator

dhi.io/prometheus-operator

Prometheus Operator 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.94-debian-dev, 0.94-debian13-dev, 0.94-dev, 0.94.1-debian-dev, 0.94.1-debian13-dev, 0.94.1-dev

Index digest:

sha256:5c44ef8975bb5cbf59b2c09daae892384e2ba2dce4ecc341c127e73d114a2294

Manifest digest:

sha256:183319825b1b5aeb89f6cfd2fd52d7c7a458507b37900d89f4a1c8c768480f42

Size

58.94 MB

Last pushed

21 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/prometheus-operator:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/prometheus-operator:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/prometheus-operator@sha256:e1ef0bc99bd446aa8fd3a44741057e095cd7e63b7a7cbc8e9f33a12695f910cd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/prometheus-operator@sha256:c8f890e2e906bd33f9295aa53f511c5e3d69e28fb09524959b49f644a84859fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/prometheus-operator@sha256:f009898819a325096861f5c7a9688ec537a4f075d83e415ce0207032c8f76376
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/prometheus-operator@sha256:92e59df76b3d39dd89669fa78031a090b56708c7a70cc1e3b5e3ebc42dd28c5b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/prometheus-operator@sha256:bc8884189d7ed5e329fb63f7aa239c1f9ae0af478cc04429cac15f24e5598dac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/prometheus-operator@sha256:e8c19427d771de2004a35a5050abbe316703dec4a03acbc06529c419e133f536
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/prometheus-operator@sha256:f9b8b7d05dc1c8e654dc4fe2d7db0a9bada5568055494bca66e24c19397247c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/prometheus-operator@sha256:543ec1e62aa1778a46aea94cb49c5b758a6a2581931a83bc617d6ffd684d9f18
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/prometheus-operator@sha256:620312131b76eb42effd29eff7927ed72d687e76e7a79c7e9a385705f460f2d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/prometheus-operator@sha256:aa29743d58c491d20319d8ebf0ecfb7fc33f7381c9c286256085564ca000a01e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/prometheus-operator@sha256:ce20e6b8a7665544e234610422e985f9c2760c68f02f2a8567f1d2db7945b697
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/prometheus-operator@sha256:be1245dea324d10cf8b6c8277077152b9e1d17f4c3cf385c360e7e5882e37068
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/prometheus-operator@sha256:1b2017e3e9e619fe62a4e46e1a448a23b03665e9febe320aa2257f8ffb3fc383
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/prometheus-operator@sha256:c0ad5f5404391c2ce47db2c9e2a22c76a2b0e21490d73b667100423d0fcbe568
SPDX SBOMhttps://spdx.dev/Documentdhi.io/prometheus-operator@sha256:5a0f38366f64a36242e676a8bc8eb0f0e56c774771221963cdd85f223b598e21