dhi.io/tempo
2-debian-fips, 2-debian13-fips, 2-fips, 2.10-debian-fips, 2.10-debian13-fips, 2.10-fips, 2.10.8-debian-fips, 2.10.8-debian13-fips, 2.10.8-fips
sha256:86fd76ec4b6d2fb8411dc4ed2c1136848a918cfdd96be3b4c5ded8cbbe3cd537
Manifest digest:sha256:a3ddbf0dd09bb2a5c141dda0bd46c727af5b0a5915738b6dad88d14cc391335e
Size
39.13 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo@sha256:53870a107705eaef0162367d438e32e1da2a72cbb3b7d361d10e507d1c1dda89 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo@sha256:aee7eeab1f932b56826eeff0aff5035ab44d4000aaa544f9fa5d0cf6ddfbb121 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo@sha256:f78ebde50409532dc5130c593a4bf3ad6499a8d9afdc6122426fc5240edb3aba |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo@sha256:57ba4d92500462afdf65146520c524729f37e612675fde747902e3b113d9ec0c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo@sha256:541b1ed7703b521d827c912369f928a00e6090456796219ce4e8514843ea5994 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo@sha256:de40e4bb7afc3b8b7fa62ce60d994f1bd1bf3dba24e887c43a14edae118eef9d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo@sha256:53f0849a96d8b7fa4c8161e6e8f848d6360da32b1375bc8e8140db677567f91e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo@sha256:4c0539e69d1eccac7b9d7ba632a7a982b637a2f5ef0bd09d70d725e67c0e362d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo@sha256:a70e5fcbfc561546921e32c8ea1ed360e5de254c6a67e2670150bd52f9bf6141 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo@sha256:53ef21c5bdd3ed83b319a2c19645f679847cccc2d1a371fe38745888c2154cde |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo@sha256:d99798ef948c13932aac12b518bf469fd944a920f8577ad29d938305a89bbd9a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo@sha256:c40d67de1667feb40e42dcb831aeb7a3c8469bcea930447f5b5e57316ac3c83e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo@sha256:59bb3c60e226c12067e691c3beff45a64675205070092e0cf5225da30aa5493f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo@sha256:c5375a59d2b3a0fe4107825917b2e04e299609687e766c93636c374186ec65b7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo@sha256:adca29973e814f292a64753603e2648c3c7bc2caa3cbad72ee32b7a1245c1030 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo@sha256:1d1cadcfd5f475c4eca51f0702ec7ffada25be58a6119bdd0bd8865eb8f3c47e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo@sha256:84f12a869f73548ae170053cdc6d7ceed95b9f4c3d1187271942b27609c5589e |