Sign inSign up
Grafana Tempo

dhi.io/tempo

Tempo 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.0-debian-fips-dev, 3.0-debian13-fips-dev, 3.0-fips-dev, 3.0.3-debian-fips-dev, 3.0.3-debian13-fips-dev, 3.0.3-fips-dev

Index digest:

sha256:eff11dec68cb5ffe61a24404b4effb9190445e2d1b92b8bcc63fe2b5b899dbc1

Manifest digest:

sha256:29930266b7a5bccb887b1b09e2a84cb7a42a8eea1d99ec4a23beeddbc2376034

Size

83.91 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo@sha256:c6b557e53897ba9a896db28ff41d96852079045d1fe5e46fc0538f86f7d29c6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo@sha256:e8f5ba8a2d381abbe837e5cbc3740c91c3a72b2e896a1f47fce14fbc3931d54e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo@sha256:cb784b924aeec58c0303e6c4f2b54407842e7e1d23249398b3b126f4e46879bc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo@sha256:1dd9b8111bd588a79fed103935a55fe2294828c613f39e00cb479c923e6faaa4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo@sha256:351b8fa6256dac5c4accdaa9b12043c8848ff85c4430f0c799322aa36989ef46
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo@sha256:1f9f73d483c9e054f8a1857944d1f957687a74aa18e834cf6c7805ed963c17c8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo@sha256:8fef076d952bd6e6fbbc4de16d121357a7bedca62aa190fd8fb6614d329aaec7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo@sha256:5d0c92862cf97249196e19076b5b83d0ff095de6cfb39565720639f41eefcc76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo@sha256:15999b0094d675c76cb34999bf0243ab7461ce03321f3786e3ae00bd5932b082
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo@sha256:6459e8e6eb1945675c69b9ef27e4845f17f41ffb2cd2c1d9297e4f10dd36c832
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo@sha256:6eb0299c4dc5211c90a8c86ee06b3d8321fb1292b765bab91efc2a9debc928d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo@sha256:6264e72d540a8849f0aad5fc036e0aa5bf5b1b30e5334d8ef3038ae7d1fe6622
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo@sha256:16a7b0434f422cdcf0098350828870412f1bb86bc2cdd89885b61228f3dd31ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo@sha256:5ab2e2c7d9dc40114820d4dfa023901908b8dbae8f6c3e5e0bfd0c3368975109
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo@sha256:cb12d51f77b740a63fc45816072ec1993b83ccc4c171edb6cb4d030942543ab1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo@sha256:de33e91b81bfaf249fbd6002f1b74a42626dddc42d7633324bf1541698cda3a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo@sha256:09185c46814623b7c876495f09dc4be951e8833d54fd10fab9fe4db969cc80e6