Sign inSign up
Grafana Tempo

dhi.io/tempo

Tempo 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.10-debian-dev, 2.10-debian13-dev, 2.10-dev, 2.10.8-debian-dev, 2.10.8-debian13-dev, 2.10.8-dev

Index digest:

sha256:4e4b7b0c1bddbe143800b4d5ca9bd8a42be743aa2d0181b948f2a667863de994

Manifest digest:

sha256:0bf639ad95ad3bb58b17534d13cbcea2e90f4e89f5e8d01b010dbd8d160758ab

Size

81.57 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tempo:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tempo:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tempo@sha256:051742fd8287caf727e223d04b53fd0139282ce3df901daaa03f8f3d1b243c5e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tempo@sha256:bbdc9b05975a7c8a2f906150ca98407210f107fe5f3db427b9efc0bd08913063
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tempo@sha256:cf9fccf0812995e324fa7d4ff36b6b3d3705cc12c9b99cbd6b7bf348aefbe823
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tempo@sha256:329de6cb8f8fd4cc7a6434a8c43d2ac62ab91751bd05a22506cceaa9d74eb17c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tempo@sha256:422ae0a2f7422ee0124b10aed4c0fc50ad706cad97a54957bd55150366f111eb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tempo@sha256:2bb1777fed9222fa3301eec848b36f1a3fec2644b1024ab1054c0ec21fb87c26
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tempo@sha256:db2da3db42597ea81fb1c0db5673460ad500eb13067c4e95de724c3c5576ab67
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tempo@sha256:c47fba10ce4653ccf198ceda177432f76f978cfc52b367418d333bd7823c0486
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tempo@sha256:b610d223c10cecf5f06f67265e4facb4f3889193dcc031c3743e75ee94009273
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tempo@sha256:508fad5a26464ab2b9af6e78ed67e8314d61a6ff6aa6bb7088608fe6e4a7cf0f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tempo@sha256:e8c3997e311235988832868bdf274e0ac17c22cca72c7a88b8cdbbec50853beb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tempo@sha256:867ca8f0030b782defeade0bab0823125cf425a6f1895d7ddb0f711e2b8fd636
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tempo@sha256:49e10bd0bd8e1cf19f7a661a26ee74a3263aaff2bb4ba64de930591ad635d104
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tempo@sha256:329afc46fd866ba3f95bb187b074c82319c00fbd6d1938ec5a48ba1a3931579a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tempo@sha256:d01b165f066f44dde0520cb53f787d59430b602ec2bc8198f180cb35e8aefaf1