dhi.io/tempo-query
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.10-debian-fips-dev, 2.10-debian13-fips-dev, 2.10-fips-dev, 2.10.8-debian-fips-dev, 2.10.8-debian13-fips-dev, 2.10.8-fips-dev
sha256:2e9fe6ef9801ed46c899d6f34cccdcaf1599d21866c6aaebc9cf4b362edd7c67
Manifest digest:sha256:a2e68c81af8d3d5c0f5abc66d34fc697fd759d77f8098b6544e17dcefbd2f102
Size
36.30 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/tempo-query:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/tempo-query:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/tempo-query@sha256:a127e861b291403a3a8a6253867c5f679e4a8079315f5bc66dbb2e58254ef3dd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/tempo-query@sha256:cdf86704a2cb95a7394181fbfa8b84a30a759866a0935f94f24f48991a1119a8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/tempo-query@sha256:78fd8d7c2078997feccf205c325a26d825bb659750c3514050b6c2c459a70490 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/tempo-query@sha256:bb2917a8a1369afcfb988c271fa7157a7057ca162d6d33e7a0d4aa269c55af92 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/tempo-query@sha256:7eccf6841ec587eefaee4378f39c8b9e5460e11539c46e111c20eb310b9e6eba |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/tempo-query@sha256:e190a1a4a24093a06b088c2674a251677747766ba31f82f064a7de6862bee1dd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/tempo-query@sha256:77ffeb0c597aac6b9ed6ad5731dffa03c6016900b8143d34c97827c98a19ce88 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/tempo-query@sha256:e248aa1e4fcbccb5c7b70bad5c9f8817d774ba25821a673eec5cf964651cc16a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/tempo-query@sha256:2787adc81960c7ebcbab0181cf37c9276f29c6198f3557adf79478a2a712b570 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/tempo-query@sha256:a22efb7ecb0d8e97432d658cecdc0bf8e7116917a10369302a915802f6beee5f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/tempo-query@sha256:41b6a001b0e0a14a68d18011a7a95fa55d7a835bf3ad05ec25cf592a32950383 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/tempo-query@sha256:f07110def4ba55ccaca19513c2ba3fd3d80113a6adfab24752886ce94f843f35 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/tempo-query@sha256:79e0959c30d6d4236daa9a02ff52bcde0e37f6402be557396fb9cf605f4e979c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/tempo-query@sha256:dd7231140a5f31e8b72068d1417906af773140f5a335cfec846fdaf8cf6d8ef9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/tempo-query@sha256:f2d97a0558d511fd3c91035b71dd9ff7ba2fabb7d3eed1149dff96c32a1e4671 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/tempo-query@sha256:d02522b4c6b5d344b76d979d06675567ac60e0662be7836ff816eba1e449bb3e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/tempo-query@sha256:a319a479c045c150fa9a3a14c4efef1c48da97ef9b022ed2ed44ab068d67c44f |