Sign inSign up
OpenTelemetry Operator

dhi.io/opentelemetry-operator

opentelemetry-operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.160-debian-fips-dev, 0.160-debian13-fips-dev, 0.160-fips-dev, 0.160.0-debian-fips-dev, 0.160.0-debian13-fips-dev, 0.160.0-fips-dev

Index digest:

sha256:3346dfb2d5c0e61c58f9044763369110c6748aacc7e3450097eb13c403cdbbaf

Manifest digest:

sha256:2d8ba22476b9ae7a523a36f10ca8f3ec56ca196b42eb0da56aaae008bfe3bb7b

Size

60.09 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-operator@sha256:713ce3e826f58961f3097db54c574e171bc877950dd29dc26beec1ae9454abb8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-operator@sha256:514c6251890cc9e71a408a345fb7c53f0b8df2881e12037aa17dc49328c07cfd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opentelemetry-operator@sha256:f8b33a6570dfa29edd0a633c927dc9fe15209af4bc679fc701e119812deb8a14
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-operator@sha256:c6469fbe3185230ee7008175c5b75ece43ee6faa3349ed9a9b1b66a62b75953a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opentelemetry-operator@sha256:1c633d6261db59429b9e87b47c19195bd8af240daf4496cfff63fa4a1eaad4ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-operator@sha256:f45c851803a3cdd3cb707c458b602b7b33d2b6ecb8221b8dd6f624cd899faff4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opentelemetry-operator@sha256:d6c32f2db8cf05aae8b653598f969db03ae489f919896368d883f198d5368140
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-operator@sha256:8d50e0180f5c5649e87cf0bcab9f9c961781ef4b08bc0a53db67eb836c58427e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-operator@sha256:651bd16cb2ff8defbad8cf615ae520a7d4894dbb1a9aaa472394129bbc0b749f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-operator@sha256:b877da146a9b19c641b0f780b8b7ffd35a156588f3e0ac0b58d31871bff0f7d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-operator@sha256:b786c5e704ef500ea8c364ad508762a98757045b97ff5a9e3f24c3fe793662e8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-operator@sha256:fa0dac2a75c78fa246e9d2002cb3cd28c064843cac963d11f1e93e61dd5c41ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-operator@sha256:964b87fa1c58640fc038228acda466330a79194f62aa69783d251b902dd19ad4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-operator@sha256:2d736c9511d7833e43bf0e33906f0105183109bfd6b2bfe583c83b1ed1d9a256
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-operator@sha256:9ec94a67f1229f2bf61883c647db6dfc69e197350b067e71e1bf01ad238c9fa0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-operator@sha256:e6a42b3845691af9c1c8757c83d36f538362e6a9d3b945fcb7dd99c2c74d34c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-operator@sha256:7618cc530679a2b916ad2f80f156ab595f89032d88bee390468e31be90af8175