Sign inSign up
OpenTelemetry Operator

dhi.io/opentelemetry-operator

opentelemetry-operator 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.160, 0.160-debian, 0.160-debian13, 0.160.0, 0.160.0-debian, 0.160.0-debian13

Index digest:

sha256:9a2e8f317d607a5f88a30a0c973f8a346075c5c05b709514e6cc1fb94c6a9c6e

Manifest digest:

sha256:644a02ad1b227ec7f0ac0553b8181086ba87a0caf7a7bfb06466ea12cf449efc

Size

18.62 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opentelemetry-operator:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opentelemetry-operator:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opentelemetry-operator@sha256:574c30fdd09240a5a4dcc7bff67738eae5bec5e91e3cfae3b36125d06f00ad70
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opentelemetry-operator@sha256:0f3ba7aa003c5e3f608bcc1dfc47584bec8fdbdd79edceec42a2b07077965580
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opentelemetry-operator@sha256:5e30f023299b5c98ff4e6697dee70282adfe075803cee83a92267835dd771229
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opentelemetry-operator@sha256:a0f1df0f662caae6025f29143797170de94a9dd3d91f6d64b86975b131f8c45e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opentelemetry-operator@sha256:cb39eaaacefab2b3117f20548cc7ffd4e2e4ae18908354330ff7c73ab346cc14
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opentelemetry-operator@sha256:741725441ed72a393d4ee9d1fa09c869c4f3d01ec7fb77f98a54881174efddc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opentelemetry-operator@sha256:59d9110917a7cf18e40e77bac3c3b396658e6c67c8d41e9c806044d29f505808
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opentelemetry-operator@sha256:2b5fe66993d45b3b8b980c12afb3e0db02793e3b333f9c2de09d048baeb92e32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opentelemetry-operator@sha256:167910575c551d0c37cf49556f416bb79e0fbd6c38f74f92af5e7dde16b155f3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opentelemetry-operator@sha256:340637582f81fe069ba7ed0d91861b7a701bdb16a97320d37e7e6c234d7ea7fc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opentelemetry-operator@sha256:c2c1ec7cc2fe5ca28412790ed51cc692c7b770470c78641e9eeee30c86703d56
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opentelemetry-operator@sha256:919f5c99d52ede2179b6de152000b7a2d4c115e18660ab35324b01f537661507
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opentelemetry-operator@sha256:d1f1978f8be942506fd156fcfd41e81e51e5ba9a26978fd117779b141f66d75f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opentelemetry-operator@sha256:dd990e25d29f6138920ecaefe071f988b02449925888bac7d7fe0f65aac8c322