Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.42-debian-fips, 0.42-debian13-fips, 0.42-fips, 0.42.4-debian-fips, 0.42.4-debian13-fips, 0.42.4-fips

Index digest:

sha256:fb09a826ea454794474f77fba00a18467c1f19796fd7f5e914eb93760c43b2d7

Manifest digest:

sha256:9ec03f8159c5de66dd49935bd3204f9952640c4288af23f6c4292724992f55c4

Size

35.73 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:cfcbe027ffa51921b05c7f0764ab3b8e2aa52ab2b598642e9d7325b6e8405422
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:8a8c84e8986bb9c7aa936c00f7fc4d95a16e2646dae8a9dd9fd19829dc9108a0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/thanos@sha256:ffbcf0c1c801a385d2c127e5ad807945d403a344978d151a594014961c67c1e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:58ee67e7ab650c6868f1085d90162797779d0c1282b18f0ddf2e86b3ff947fc8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/thanos@sha256:8ae0fe175755505929083c92f8ac12b99ecb33fd858a8c43b783f86f62715c48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:a162714613ae132b397c4e956935a26312ee68af8392690b097e88bdcdcfa700
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:93b8e72ad9050e357d7cf469a518f83feb27643d7b038e7c27591c6704b995db
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:51dfccd5840ef5758343d1de83271e300ea58b7b9d258d97ab328ae5eeea8d5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:09ef666bca491e604927bce717eace97a631c266ab6a0bdf041760b0dc249e62
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:3f729d8e38ebcb07458a3f11eddca885f39cf51ce3889ce0edacacd857ec0155
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:3cc1ad0588119d36708dbf44089d7f1e657fee2bc4b13de50cb8339c9fc6cd53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:e9d529caad204a34ff9c6e2cf73c8657b9d896e2c95a54658f69917777281470
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:beec35a0c2b13ef0d2f7e5d3a9cbb713f39165e60ac4b0c8b11842fe0bf744c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:f293d514484b86c309e1765a727c1211449e8648a74321fc752961fed6dc4656
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:d6e0ef1ac1d0a88e3e4914f714fe53f715fb3ce9e1e89a03e8213291c6ca3881
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:ef48b2345d12abad3f3f9de32840dc902d98a41ca95f5a465bb44b0b336de442
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:a22d5d65b5e875d16c057df5b6d18c1da5480410b266bd64996768eb647a6ef3