Sign inSign up
Grafana Tempo

dhi.io/tempo

Tempo 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.10-debian-fips, 2.10-debian13-fips, 2.10-fips, 2.10.8-debian-fips, 2.10.8-debian13-fips, 2.10.8-fips

Index digest:

sha256:86fd76ec4b6d2fb8411dc4ed2c1136848a918cfdd96be3b4c5ded8cbbe3cd537

Manifest digest:

sha256:a3ddbf0dd09bb2a5c141dda0bd46c727af5b0a5915738b6dad88d14cc391335e

Size

39.13 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo@sha256:53870a107705eaef0162367d438e32e1da2a72cbb3b7d361d10e507d1c1dda89
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo@sha256:aee7eeab1f932b56826eeff0aff5035ab44d4000aaa544f9fa5d0cf6ddfbb121
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo@sha256:f78ebde50409532dc5130c593a4bf3ad6499a8d9afdc6122426fc5240edb3aba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo@sha256:57ba4d92500462afdf65146520c524729f37e612675fde747902e3b113d9ec0c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo@sha256:541b1ed7703b521d827c912369f928a00e6090456796219ce4e8514843ea5994
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo@sha256:de40e4bb7afc3b8b7fa62ce60d994f1bd1bf3dba24e887c43a14edae118eef9d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo@sha256:53f0849a96d8b7fa4c8161e6e8f848d6360da32b1375bc8e8140db677567f91e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo@sha256:4c0539e69d1eccac7b9d7ba632a7a982b637a2f5ef0bd09d70d725e67c0e362d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo@sha256:a70e5fcbfc561546921e32c8ea1ed360e5de254c6a67e2670150bd52f9bf6141
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo@sha256:53ef21c5bdd3ed83b319a2c19645f679847cccc2d1a371fe38745888c2154cde
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo@sha256:d99798ef948c13932aac12b518bf469fd944a920f8577ad29d938305a89bbd9a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo@sha256:c40d67de1667feb40e42dcb831aeb7a3c8469bcea930447f5b5e57316ac3c83e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo@sha256:59bb3c60e226c12067e691c3beff45a64675205070092e0cf5225da30aa5493f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo@sha256:c5375a59d2b3a0fe4107825917b2e04e299609687e766c93636c374186ec65b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo@sha256:adca29973e814f292a64753603e2648c3c7bc2caa3cbad72ee32b7a1245c1030
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo@sha256:1d1cadcfd5f475c4eca51f0702ec7ffada25be58a6119bdd0bd8865eb8f3c47e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo@sha256:84f12a869f73548ae170053cdc6d7ceed95b9f4c3d1187271942b27609c5589e