Sign inSign up
OpenTelemetry Operator

dhi.io/opentelemetry-operator

opentelemetry-operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.160-debian-fips-dev, 0.160-debian13-fips-dev, 0.160-fips-dev, 0.160.0-debian-fips-dev, 0.160.0-debian13-fips-dev, 0.160.0-fips-dev

Index digest:

sha256:9cfa7f10f834cb327c24f00180e2041ea6d431352903c1a223aea0558c1ffffd

Manifest digest:

sha256:7675befa4e0680771f0556cdf8938c8ec976d8c5d0d2a196681e33b7cb64f9d8

Size

60.09 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-operator@sha256:24de9e35495502853c6ebc1d07978e867ecddbfba2060738e8f16c2837495915
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-operator@sha256:c0fd3a8c5e382eae121e9d079e52164792852bbd86f4068b52f6e26dba34d6b5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/opentelemetry-operator@sha256:b8b1b362c1b952828901a9b81682b834b76b2d2a84ecaca1f829ab7ef345db92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-operator@sha256:d51048d79550760421c23317e70fd6f2d2b240c7ea4b3e37852fccbdc7eb1b15
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/opentelemetry-operator@sha256:db79b127ee34c561ce718237eafa98e2238faad795af121d369fef437f6d5f7e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-operator@sha256:582e644f9d62052ad4d5968e9ee4509d504eb2a658f9f232e8c478ea84c03440
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opentelemetry-operator@sha256:026bf867106daf583d0ec980e6b4928188fee4eff092dba4d1c7ac168f227d8f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-operator@sha256:8dc4c5b976154fb5ad83aab877582b5e5be2f123c6704507300e59bc440f9982
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-operator@sha256:1cb038c251db2a25bd8e9718d610c4a00e7062e79759f60ad7c6afa684869707
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-operator@sha256:2c077981f2387d301ef377e8bf4f0e7987efed35a076ab47d151a115b50136be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-operator@sha256:46df33e9be09aba44e69f582ee180d6caf7132039f1447bf02122cb4242c462e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-operator@sha256:82bd8dee3d0d751be23c669f98546abf1311ca250b9ec40a5e660ca1a5aee64e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-operator@sha256:ed8f87f330ea8da9fa714e5b0d8fa75ba3a46781262779478cb24cd60e103ba1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-operator@sha256:b152c794f0e1252406ac29d105dbd60c985a1ad9a0c5b4c104cd680b01706f1e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-operator@sha256:4663a7c6481a386ed44bf24fd99b04c6f34debfa8d262264c0ba2510d3772b4f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-operator@sha256:2bd356aad490876f3d68cf9fd286f17a08c3938c6233b6f1f97fef9af0c04f73
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-operator@sha256:fe00c1fbde8daba3c8d1ec154c1e3031968ef275601ce600b5c64ffe53b41219