Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.42-alpine-dev, 0.42-alpine3.24-dev, 0.42.4-alpine-dev, 0.42.4-alpine3.24-dev

Index digest:

sha256:493b456330c47add4e38332bad5ef188fc3c1974a9c74da16c08d3a30ff508cb

Manifest digest:

sha256:a18984b064cd5b7c61e00fa01ebf0b381844f8ca563979cef25e4bfa5ae84e73

Size

53.63 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:75c39419e34fb16188a1af706423f9a30f4d9041336f5402b420066e3567842c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:3e0ae00567810f0471a689f7c6e0df467435871451786075cbe90485c5b6b171
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:074f37f9fbec06e922e7ea5ffe4451db35f088b1aa5d0542f1761d9089c80e9f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:d26d917db1a9414faf5b5d5aed163bee9bb4efd107202a4b2f3348ce4f56bda6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:0c26c4ef1602eccce3ec2243e2b5d2e6b566fe4bf1fdc6bc4b59abecdeb4c091
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:ec3cb0a8417dea999c2c1dea77e0575e1d2996bb34d4a26d0ff092c537e2f375
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:4906c162cd7d5921eedcb3b28f7efc39c7a3e9cd56c2a9d4a23ed82e7646441d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:3dd0aa78d7aaec4c69f94181ca9b25e673812b34e0fb8bd63b3acc516f06493d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:b33e511111163849795647aeba9e60aa578f1160ea761c74656a3d854609e2c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:e5b464e498359134fe81f3fb81a9f512aeaad72febeb7ebb535e46c810e02a24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:6e5e55bd7887d07718b84ea0ac5183ff8c8945686175e395b5454681c7ced1af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:e2e0f3e9b490acdaa6bf2cdcd899ec7b538f5ef2042ebc51f50c9331e32588d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:5b5cce8cd77d8d7c6ffd71efac288c2782073396a56edc0cc0bee8bccfec87e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:1154c2056841d98401868d15554f057fd1960a7dafa3a1dc9c14f98f78e45168
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:8dc1c4e9190e2b3d07fcdab4fb6f05ce4eb9242662b9b68369f8ad788300ca8f