Sign inSign up
Tempo Query

dhi.io/tempo-query

Tempo Query 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.1-debian-fips-dev, 3.1-debian13-fips-dev, 3.1-fips-dev, 3.1.0-debian-fips-dev, 3.1.0-debian13-fips-dev, 3.1.0-fips-dev

Index digest:

sha256:0ddeec618b61d784958d944af2edb3fb90144b84729dfc9e3fbba35ecafcf1b4

Manifest digest:

sha256:64e2346bc70dd87c9da92d621f50b429ca51f91a9ba11253e3fe0b3dcf067854

Size

37.15 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo-query:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo-query:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo-query@sha256:bb4d177aa9ba144d390cccee4e278f8b5236ca0857f2d2205f33862ed02dac6b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo-query@sha256:b353d534971aaaa6952485581f9d7090ba3d50e22a8d3eadb6276ca1fa86d791
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tempo-query@sha256:80717951d5a4553385066083c5be198d498c71d47f5b0183784ba3fb3c41e44d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo-query@sha256:a4471b39d0b3116b18296393178b9c8d8c3a0506171eb612d0fc3de53fb8f38e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tempo-query@sha256:20fd9676fc2ecbfa57e61e71ef94963462674388354fbbd369cf6bc61b984695
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo-query@sha256:c1b40b3cd6e22369d4084426716993ee4d0599c9942fc76d73e258bfcdda6e7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo-query@sha256:cb13349e33cbf545776bdf0c5eff781991cf8d083d45c7cc2d49bf88e12e22ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo-query@sha256:51507e884c92ad1ab660a42607587a64ae51471b58c87cbc232cca30df7a13b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo-query@sha256:0290413f18fd4e92be8dc977b37940642e688e81297a14f2736456d8a7245d7d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo-query@sha256:07949d105b1bf78fd6c72e8c8d76064a63fe9889497dd0fa01e8df7e069c8417
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo-query@sha256:db669d8938db91f934ef0b89d068aeb2f10e2ed004e853dcb01dbf57a78b990b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo-query@sha256:3470d01e630992123922ac1fcce2a567db096af371520b0c7ea189cd519e88a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo-query@sha256:e9461eebecddb931e76019087b022d25d06a5c9b37e60e22169e56877cf86244
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo-query@sha256:b1941a6f0d3fe3d1061bb3b026721863cec541598d585bd4faab05e16fe32a76
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo-query@sha256:4557c976f7038c0dc88275e732af653d15c0b0c1ceff391591e396a5a78b5fdf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo-query@sha256:b3c372a7c3db6b102ec8abc76b1413d594ffcae4b6de845eb8208c51a0bbe970
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo-query@sha256:69ae3bac5bc157678d52031a2bce779227f4879ae05bb1654b8bbae8eba8c52a