dhi.io/opentelemetry-operator
0, 0-debian, 0-debian13, 0.160, 0.160-debian, 0.160-debian13, 0.160.0, 0.160.0-debian, 0.160.0-debian13
sha256:6580350111798a415eed0b3bd8f569cee95c66db96c4eb546fba4633ac041d5a
Manifest digest:sha256:0e7d299d363e611ab3a11f3ed5d5d94f489cde9c9ee4e2d892880ab1f6ce5374
Size
18.62 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/opentelemetry-operator:02. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/opentelemetry-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/opentelemetry-operator@sha256:e85566720add8418112122eb087635aa36f2d5b45cf1b76c1919a6762d0da1e4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/opentelemetry-operator@sha256:e0b6351db36b02e2321aae3957618b1d35dd5f433b3664a8e91eb55ae0fe854a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/opentelemetry-operator@sha256:ffb866ae8c54b971ff6d6f9a4a4c6cb4df60bd92312781c03f8dc0da5a80fe1b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/opentelemetry-operator@sha256:99ba2e432585de260aeecd6793c44df789722bbde38423b5605bd584fb351ca3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/opentelemetry-operator@sha256:2762ab3cbcae8b361d38adce859f294a4f6a355d71875ec9cac516efdf550bb3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/opentelemetry-operator@sha256:b64b8d6b814afb1b1f419d8ed932eacbe64d50ab28f5ba47a561e5d38614cb7a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/opentelemetry-operator@sha256:8a99d9675d4e9d78db410f9090a9108a51922436873ca7a2b0aabaad66ffbdb8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/opentelemetry-operator@sha256:f35a474ed3124a2013a711115638776572f62d15e55714008f5e5be4902b874a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/opentelemetry-operator@sha256:226eefcb3634a63a220f64b5bbe20426a8b9c59a752bbe55f7b02edece47076e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/opentelemetry-operator@sha256:dc2c99652f0244c6b1a418daa7650dcbb3bd7291d23712fcf83b23ac1ffed25c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/opentelemetry-operator@sha256:8ecfcda18104dc97872d51192f45d5046b688c5ffdec0fa99036aba02af88072 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/opentelemetry-operator@sha256:bf1cd30ce83920e7ee290f728345a55765f806461df97a5b33b05269dd393a2d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/opentelemetry-operator@sha256:b8f8f9d370e9dbe77dcdd51bb9000d0ca7919febf0535d0765f8c301baf0325f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/opentelemetry-operator@sha256:e884001a0367b14f144e5383ef8f7cfb6d063ad98e2675a0aeb774486e6b73bc |