Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.42-debian-dev, 0.42-debian13-dev, 0.42-dev, 0.42.4-debian-dev, 0.42.4-debian13-dev, 0.42.4-dev

Index digest:

sha256:7bb87f5a3aca00b61a3d65a4cbd320857e8fd55172e085fbcb01d53d2a79bc35

Manifest digest:

sha256:072ebaccc53cb91ea8647220ac2b60d93fdf94ce20e2e93579da2772f2fc9c09

Size

72.98 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:4ab9f6bd8d44c684839475cdcb7e769a54ec15266b46232678caf451e60abeda
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:41645476e1948d47c20ed82d5576ac9f0fdae6b5c3ebe49d61cd1e95cb45f16d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:6ec45d415f59a54b8a323283d69213a1492d5c5d5ad8d3f6329f8a7d8778d15b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:3405ace1bf1cd8636c9fd111e9c58550cc1ce0c292c4db99983757b10b427c3f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:0bc4223a9cb8f92fc9936845bd82ad33106595a3bf96b7d86162c1b7df5852e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:71643c2c7771cee73707b80521469ec70cdc1520282fff49df6960ac1eceefdd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:c4ee882c85f462253ac840cb937a78b81dbf3b3f81fef01e9afe9448048fbeb1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:a60bbfadb9ce1a36cfe433f88e9446b88006d08194625d46e0cc0ce77352ae9d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:4a2661d80e466b387411acb70cceb1cd8b6d0c5a81ddf68b3df49493f834d291
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:a926c41aaf457fd70394e146d1b52dd1166640bb6f239db7c6f4789a8e60858f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:a97d0d5f5e84954587142d97478832537bc5e0bbb098b859465f4b5f959addf9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:8110fa706c2e972b0f8a0954bae2c6e70f86eaf75416417589411e43bd30ffde
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:8821c124c7368b3938cfbfe5df4fee0b518d99825872d4bddeb08821f84c2551
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:d9024af954f15afa079df3093f91c063fcae69c4cefe6e0ce521a458f5c0cedc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:05fd8357d860c82ddb263501f52bb6926403841bd9e3dea2c0f53f050311ceae