dhi.io/prometheus-operator
0-debian-dev, 0-debian13-dev, 0-dev, 0.94-debian-dev, 0.94-debian13-dev, 0.94-dev, 0.94.1-debian-dev, 0.94.1-debian13-dev, 0.94.1-dev
sha256:5c44ef8975bb5cbf59b2c09daae892384e2ba2dce4ecc341c127e73d114a2294
Manifest digest:sha256:183319825b1b5aeb89f6cfd2fd52d7c7a458507b37900d89f4a1c8c768480f42
Size
58.94 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/prometheus-operator:0-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/prometheus-operator:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/prometheus-operator@sha256:e1ef0bc99bd446aa8fd3a44741057e095cd7e63b7a7cbc8e9f33a12695f910cd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/prometheus-operator@sha256:c8f890e2e906bd33f9295aa53f511c5e3d69e28fb09524959b49f644a84859fe |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/prometheus-operator@sha256:f009898819a325096861f5c7a9688ec537a4f075d83e415ce0207032c8f76376 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/prometheus-operator@sha256:980fdf3a91d8f8ff91451a5339e7cd9567b2b9fd977b5e889d4478ee4355a4dd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/prometheus-operator@sha256:48300a71183b4d0d225b5f6aff9aaef0839110635a21bb7669dcbd35a87906c7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/prometheus-operator@sha256:e8c19427d771de2004a35a5050abbe316703dec4a03acbc06529c419e133f536 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/prometheus-operator@sha256:f9b8b7d05dc1c8e654dc4fe2d7db0a9bada5568055494bca66e24c19397247c3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/prometheus-operator@sha256:543ec1e62aa1778a46aea94cb49c5b758a6a2581931a83bc617d6ffd684d9f18 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/prometheus-operator@sha256:620312131b76eb42effd29eff7927ed72d687e76e7a79c7e9a385705f460f2d8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/prometheus-operator@sha256:aa29743d58c491d20319d8ebf0ecfb7fc33f7381c9c286256085564ca000a01e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/prometheus-operator@sha256:7245e36b5221af3043a12133766bf23daec6d970f062ae7a500efae726286e99 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/prometheus-operator@sha256:be1245dea324d10cf8b6c8277077152b9e1d17f4c3cf385c360e7e5882e37068 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/prometheus-operator@sha256:1b2017e3e9e619fe62a4e46e1a448a23b03665e9febe320aa2257f8ffb3fc383 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/prometheus-operator@sha256:c0ad5f5404391c2ce47db2c9e2a22c76a2b0e21490d73b667100423d0fcbe568 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/prometheus-operator@sha256:5a0f38366f64a36242e676a8bc8eb0f0e56c774771221963cdd85f223b598e21 |