Sign inSign up
OpenTelemetry Operator

dhi.io/opentelemetry-operator

opentelemetry-operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.160-debian-fips-dev, 0.160-debian13-fips-dev, 0.160-fips-dev, 0.160.0-debian-fips-dev, 0.160.0-debian13-fips-dev, 0.160.0-fips-dev

Index digest:

sha256:34f6e8fe2324b096537935653773d50ac2fb978bd0a449d0fa477722852453fe

Manifest digest:

sha256:6a0def0d81d8a065caaf4233f1c74989857b3ead048de89b868537fb3c1eba14

Size

60.09 MB

Last pushed

2 days ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-operator@sha256:947bb6347b82692a83b86a04cfc04ab610bfa549502525ca454f954e3a4780f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-operator@sha256:3e38d0a9fd7753c053a620471011d9815640cb20147e6b2a4c328590baf7a46c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opentelemetry-operator@sha256:57221d85b39b40d53ee9436dede5cdcee7490608a5438a7ac05f2e63295db589
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-operator@sha256:da8bf41fb1c871751d1003d86dcfae31603fefad46e568e62c6ab4fba169e76c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opentelemetry-operator@sha256:6689f5c7c42c10a56ea8bfd6bc1f9584b55c4e821f4d5810d479c47ce5d50d30
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-operator@sha256:4715fa73eff18fb3d9c383dde62f3d4378ae5d985e91dd16bb66a413ece7c297
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opentelemetry-operator@sha256:e2ac7a0be9f6cb89b0f3d3a314bc436de8e685ab50c578fbf346a38fd89cf039
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-operator@sha256:b3943558fed245bc7e288f412dd098c2aa716748350899ab7116b0e67c28ba05
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-operator@sha256:35b10315d075a6d4767362927ba1626dfe3c0ff2916e3c610ec53b605f065c7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-operator@sha256:cf14f66f95fd308e67871e5b80e78ff69ad6c7438ae846a7270676d183891bc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-operator@sha256:8a9d72c288ad7a78a329a1918eef08347298bba717554c30abb797f7661a26be
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-operator@sha256:6bb2bc0dd28bc5712336cee5a48dadfe744f9876443a91a9d089904b62fea95a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-operator@sha256:c780a243e4d36d8308afceab5cb0e409bfa6a46d447c08d501682e36509dee3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-operator@sha256:d6df47be93ac20619b528799354ff2761e145c77350efd218c59bc94899330de
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-operator@sha256:6923dd399ff7c7cb03b53bce7f5306c7975b6ba23a82a3e3b14d68d10ce41163
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-operator@sha256:a3bfe6df820fdad170adebec657e4e778eca98731dca9e401d52ba59cbba84e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-operator@sha256:a4addde41758603062952c788b404ea379dc20b1c470d7e27a1b1accb84ed1cc