Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.42-alpine-dev, 0.42-alpine3.24-dev, 0.42.4-alpine-dev, 0.42.4-alpine3.24-dev

Index digest:

sha256:f2583bacd48a1d785d028cb96759d4a7142cd386e4cb36c671590fa1ce06fda1

Manifest digest:

sha256:bf4eda53fea673acef3ea82dc714f6375603efe380f0fc80ba903445d014cf04

Size

53.76 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:35ddb30039b5ec5e396ec60d00a0bf35755da796a2f313c2f0fa8c6f4720ed39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:2f746dc5c175b389c000de033ed366d5dd3e67a2407d781992ca26ee34e597a4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:6fcf11d805e0eb738c1600e37135edd1a94716caa0ba0bc19ccc0e14ddc4b1de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:f51bb6fd95488d13fda5a5527e335e6caf1a7e982e0a6ef9bb16aeab42719757
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:8e87957335164f338a706e3b3ef215c261f355e8b11f814b35b0b98f6c3e6aaf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:83bd8ea55557c00790d56eebf09afa6813a17bd7afa809cedd4772af163cd91e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:d04c24eeab45e7796a4e2554e9507b8256d71e7c22639a4ecaa3dde6f4f38c2f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:711c0cd8d17013aefe2e5ca869d94de4bb8082bf3323f731f66023ece19ca38d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:5e065f86788e9dee47b942be65e829c8b57928be3912fcad76b71b6baad733cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:d6e831151b164deb00c92c125d9e3b7424476ce44a128db8012af4af65ef34c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:30542a43d2b5af865458511f08e703fb95e0726928dc4cd4f6a397c32f71cf90
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:f11dd7adf2d41619f213b283e899fea67fb754acd8ff9293b0de6836a64d6b2b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:ddecebd0cef4eff0abb71758696bb57380504e7070c19fa6c52b41b87948d36e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:f7963c6ff5bf6a3b0ed5bc59e5ec3c10647bc4c998fc4035fb0cf8dd5ff7c502
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:5fe9552ff57a66e3ae82b1504a4d5092c1fa4a5efc700bd6e07b41a9a7c251ab