Sign inSign up
OpenTelemetry Operator

dhi.io/opentelemetry-operator

opentelemetry-operator 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.160, 0.160-debian, 0.160-debian13, 0.160.0, 0.160.0-debian, 0.160.0-debian13

Index digest:

sha256:6580350111798a415eed0b3bd8f569cee95c66db96c4eb546fba4633ac041d5a

Manifest digest:

sha256:0e7d299d363e611ab3a11f3ed5d5d94f489cde9c9ee4e2d892880ab1f6ce5374

Size

18.62 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-operator:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-operator@sha256:e85566720add8418112122eb087635aa36f2d5b45cf1b76c1919a6762d0da1e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-operator@sha256:e0b6351db36b02e2321aae3957618b1d35dd5f433b3664a8e91eb55ae0fe854a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-operator@sha256:ffb866ae8c54b971ff6d6f9a4a4c6cb4df60bd92312781c03f8dc0da5a80fe1b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-operator@sha256:99ba2e432585de260aeecd6793c44df789722bbde38423b5605bd584fb351ca3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-operator@sha256:2762ab3cbcae8b361d38adce859f294a4f6a355d71875ec9cac516efdf550bb3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-operator@sha256:b64b8d6b814afb1b1f419d8ed932eacbe64d50ab28f5ba47a561e5d38614cb7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-operator@sha256:8a99d9675d4e9d78db410f9090a9108a51922436873ca7a2b0aabaad66ffbdb8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-operator@sha256:f35a474ed3124a2013a711115638776572f62d15e55714008f5e5be4902b874a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-operator@sha256:226eefcb3634a63a220f64b5bbe20426a8b9c59a752bbe55f7b02edece47076e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-operator@sha256:dc2c99652f0244c6b1a418daa7650dcbb3bd7291d23712fcf83b23ac1ffed25c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-operator@sha256:8ecfcda18104dc97872d51192f45d5046b688c5ffdec0fa99036aba02af88072
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-operator@sha256:bf1cd30ce83920e7ee290f728345a55765f806461df97a5b33b05269dd393a2d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-operator@sha256:b8f8f9d370e9dbe77dcdd51bb9000d0ca7919febf0535d0765f8c301baf0325f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-operator@sha256:e884001a0367b14f144e5383ef8f7cfb6d063ad98e2675a0aeb774486e6b73bc