Sign inSign up
Grafana Tempo

dhi.io/tempo

Tempo 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.0-debian-fips, 3.0-debian13-fips, 3.0-fips, 3.0.3-debian-fips, 3.0.3-debian13-fips, 3.0.3-fips

Index digest:

sha256:68390199a80e261e2ff280e204850df1ad78137692ab080701b5145e7769e922

Manifest digest:

sha256:f1d1c6f7c2e8eef30ad7574be0db4d269e6540f0c94b05414d868563f2d20e77

Size

40.06 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo@sha256:8a437adeb235db4a27e6703c8f0bff83c4936d415358b1af3d37bce9ddb0e021
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo@sha256:56e929b3f5cc4156b5b8cbfa086c0fdf2f9919c99aec31ea484a4151545ec1ef
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo@sha256:c40f2a6d583cd4ef4ca5005400edf2c1626efe4be02d8cff2928f2a122f2e686
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo@sha256:2d5a1ccec7045fd453fcb10d32185550a6c2753729523b20dbe8965310588d62
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo@sha256:953192dbcbac4ffb220c3028946694b28eaf9d05db3a030706b181323b3eb23e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo@sha256:9c4a0ee063e5a7f734726d731b0a81e7bfd34928ab4491ddee8a0184fd7a25d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo@sha256:4434ec2f2d4eff55509d8a3cff19bfe58da2ffca83683a629a2deb8fa46948c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo@sha256:19328d3fc2aac5057fb986819e5dd9246ef14922475cf3a236e69e5bf418edac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo@sha256:fb79fa9c864e80fc41747c984da261cf842da440b384359f5b778941fdf6c335
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo@sha256:14adbb16e7449ec6426b3f5b6c287f74601cacfc50c99d25abc34d26a7c097c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo@sha256:7783a3451e51b0ed081a1f64caf4e8d227ce7f4ad4763e1ff9d8f3c7be953886
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo@sha256:a01273fa8d04259a4311fea4299ed0438b978384f193543441bb088928a72da0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo@sha256:21932f33918973296219353e9f131963e242eace4651092b760f7cf8f0e09943
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo@sha256:9e22eb5b39ed601f583d8f77e4117e384f67e5a894c1da401f60854ce21ca391
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo@sha256:1bd515e61472c1b24d89c952f674ea4793e99e280bc6434294c29101cf826404
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo@sha256:59bfc838e7407313497de8d7aae9332669f57bc7cc261c26bb1877923bd64363
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo@sha256:fe94af7599b9a913429524caf5d4798a80f2caea860eca469c9284dfcc35b7fb