Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.42-debian-fips-dev, 0.42-debian13-fips-dev, 0.42-fips-dev, 0.42.4-debian-fips-dev, 0.42.4-debian13-fips-dev, 0.42.4-fips-dev

Index digest:

sha256:a749fe50acf0be2a57fbe63d4b46666869ac7c593e1ce34d0f6517366dcbef40

Manifest digest:

sha256:03316ff6b265329bdde9bb43142d6fc12ba0f52a77351c2ff3194d674ebefab1

Size

73.93 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:6197d6c7680484b559b434d03fc8c7c641eeed1e2fdb22ba2a04b6c1f2027d86
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:12074928aa6d1abfc970148ebbfd570e12b65e72a41c70eedc5b8176af13de30
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/thanos@sha256:7bf8063510a396040d3ae63f423777ce52e9fd411f61fd909f391fb722060c6a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:80313df2dffef7d7f3e252b7e5b04a2ea1d893a0c8091f8855d20922c4be0448
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/thanos@sha256:3ef9399ca97241bb3cb736cf30d1f85b2685545d3ceaf38bc6b9576d9b4f5223
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:e958f96355226397a59f636d777660dfebf637cfd7e2d4733e39102527c95c56
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:9162f5d70a1f12f5237f02f05b692ddda6d2a3e57e3f7cd9de6750a0fecd2137
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:97906cc685339c67209e9f1d6e1258a925f8709f5020c72fcd1c97297d8ed9c6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:c2972110c3a327fa879448ec044b19d83fc652f170aa8feeea264396ca35923d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:979bba5522fd192ab3f4b489daa6c0860c71f6abacf025ee05d0c7d48e1fdf04
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:4d1c7185b439b1653ab3d60a9017f80e5535b97f2153501a5d07c15e90a7cc17
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:0d169368bcf1e14d43cded7da28f0cae3873b244b50c872c01d192d845d3d90d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:f809bf7c89485cfc330e44f52e6917a6052d6fd0eada03de76a422624c831290
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:9a9d283d7cce551ed5e62aa7c8c9894f7d27bada5491b2ca0e61a8a030ceefc2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:e0f1a0dc04cd5574e45960eeb33be68ec5ba1af92160e2f6de1381bc34243fe6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:c08cd58767cbb1bc8b087c7479c15e4222e304ddbfc13042dd8f612a04129492
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:3962a31c3026ec010e44cd09f55dd62261df961fb3fa704e178707f1e41963ea