Sign inSign up
Temporal Server

dhi.io/temporalio-server

Temporal Server 1.30.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.7-debian-fips, 1.30.7-debian13-fips, 1.30.7-fips

Index digest:

sha256:1753d8064bafee663c1fcfff22087de5c408818c5b3161cb73cc08f2afe48b1d

Manifest digest:

sha256:8fa7e4c7c910cbfc353eaf23bdd303e93d41d5fbd6b7e7070edffb00fca4545c

Size

40.23 MB

Last pushed

20 hours ago

Vulnerabilities

2
9
0
3
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/temporalio-server:1.30-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/temporalio-server:1.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/temporalio-server@sha256:99cd2ec32d89ee0153f687e2b5678a16c22a75ec79ffeef36015bcd6ae7e0347
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/temporalio-server@sha256:9eef4ca921d2ef9940dba2ccbbde24f4580c13faa79d044b110d2e911d098c54
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/temporalio-server@sha256:0287511fc2d71add2c5bdb84d31eaf2070436921dd49e10c615932c1001c4816
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/temporalio-server@sha256:e72afd41312d404b5181bbfb70e181afdc7b854d4d82576bed3785a40781e9de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/temporalio-server@sha256:99e3833296e67af9c9bb60f1a9dbd7eac8093069895f442e2bd600168413e41d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/temporalio-server@sha256:e158f3bd4dcf1ff4696e7cbd564e9db8019fa053659f363b9a3695fd67123266
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/temporalio-server@sha256:fd0972e2b63e47f6ebc1a990631edbd873e16eb419a51074050fbe024eb450c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/temporalio-server@sha256:04ef47967726c5940aa06b374371764550c1b6787a5a6706de261b2c0b747758
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/temporalio-server@sha256:b5423a607fb167cad18943aed53b7a62ca0941ec5c310142f7d4c3fdbc2e2e17
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/temporalio-server@sha256:31b8284331adbbfd4dea2a265c162025a9de31b5e08498d0794e17a329c1e601
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/temporalio-server@sha256:e3b960b1a629d8e72d1ad21ed87cdca5d07dc3a9f955a017592c3492e78a1ca0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/temporalio-server@sha256:943d6e5eca9c400b688d6db88c53c64e6d793defd02cc78dcf0a76e2db3182bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/temporalio-server@sha256:2bf6aa43f64f1595b06dc79300fa1947eea2f776aeb536c01f407090ad79246a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/temporalio-server@sha256:beb0495d68a1ed9b2f4feb5a4647a87c1c193050369b86416a45707240ee8e5c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/temporalio-server@sha256:afc79b3348f9f9e4c16315be754ed82e27b61fe79cbe3852293a334b5b4eb19f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/temporalio-server@sha256:75f2502dc448f843bd0bbd8a429fd6f846780afeca32809496d3a461dba5d4e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/temporalio-server@sha256:8cdfd41f7d9b47b27d57e8d650109a49d6af29f2f02da102c62b222b9206a02b