dhi.io/tempo-query
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.1-debian-fips-dev, 3.1-debian13-fips-dev, 3.1-fips-dev, 3.1.0-debian-fips-dev, 3.1.0-debian13-fips-dev, 3.1.0-fips-dev
sha256:944d70ef34a2058da7bef082a0a37b61d038fb9ca417202f950d5ce189ccd97e
Manifest digest:sha256:a45804ac951f72623063a070034de5633274b2e6b7f2a8d72a20fc73c2c2abbd
Size
37.16 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:f77db3c26d0a2eb5d3b187fa33e8328d5cb697a7f6a1c0398dc183cb6e8041b8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:66ed0764e2e5291d889c47642c5b2d374a8a3898a66bc93648dfda3bc5a8e9c7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo-query@sha256:9d69c2d18c0d7d450a2598452dd46803d18fae28f429771694b38d49739cd97d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:c44954ef30ee398961a156dff8aa6198de204f83716362a01072a2e44be2f991 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo-query@sha256:89837cd61fe5272ca7d5b621036a522209768beb77dea983ac6d003e6e8f01f6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:4ebf645a1a9a6006ac7f5d4883bfeeee43bdd73a41eb419f07e2900a0d128789 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:0d1debe1c9cf6438ce3f69a9a35a06549312f8391ae0ef1574fdb4ddf0ac7903 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:0765375150329d10d9e538796aa3cfedc0a7a3d5f337f37ace4ed2bfd1290d62 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:a8f387a33fc706df6bb43496f2747305620c046d6a18f1b49dae49f2424e2833 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:f1936ab75c546a55e64a1814eeaf709bcb995b9f30fbd7b62af7a665145aa67c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:1e2e634889eef85b6c4f07307c82c01dd7a5e814cda3887b51ca9cad19633d8e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:e7e12dfe7385cb9ec17421f024270554115f0814ad568311df826dfcbc081e4d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:c8a51b91923114cc4a5aa79c2c401bcfa9f966a300c6c0fd150e071109fbb883 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:7d56c49396bd3e2552c243337852d349893e180fbcd3df9e73334e93fafa595a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:2caa32dc20aba3b28ea07905e7b8a59fd48abe10a580f329f66b802ed8acc824 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:5f23e99c490d7422c459856a4b53205fa01a9a9ad30c1202647aa2c607860baa |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:8049a7b265c6e1b2d506b1182bf3430752bbec29cf53ce2a693dc95e2f0a70dc |