Sign inSign up
Thanos

dhi.io/thanos

Thanos 0.42.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.42-alpine-fips-dev, 0.42-alpine3.24-fips-dev, 0.42.4-alpine-fips-dev, 0.42.4-alpine3.24-fips-dev

Index digest:

sha256:69c31483815e6509309fbb264b0fa7d2886d52fa0c3293a493f9a2819bb7b274

Manifest digest:

sha256:130aaac8bd67b7941cd8a0fd2458872cb4ac58a20b7cc820cf3d6f48e517d11b

Size

54.62 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/thanos:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/thanos:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/thanos@sha256:090b085965150084d7536847d0f43cb6d781b54657df8f63dad756d763613214
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/thanos@sha256:17e83f427177d0252bdc66a5b21c796a1b140e90f34809cf19063fc82486d7e9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/thanos@sha256:b7508cf565073886bd1bf7d1fdf859ed6c25ca0bff9c3c127538bdf09a5b059a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/thanos@sha256:577f10de2f3f4afd2e24184f529a8477abf6d8ab4003d8fcb92766e68199fa9e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/thanos@sha256:4b831766f25f0f83c26bdd37af71ee439609ecf6f57665f962fafede08b69c40
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/thanos@sha256:6bd9eea12e926ed5775a746a13bb9c42f55cd31d1cbeeab0ba3680ce071d7bb8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/thanos@sha256:b5a3ebb7e7f0df4aa6b2690cbd9409cadaeedbab9285a3c4db02e27829063500
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/thanos@sha256:98c077fa53d394f03181d6629b05670e08c0297f4c56c31cf46d2cc995937f5d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/thanos@sha256:92522dbc5e828d315e45df7f82320bef5fa4864f7ae938879811b6292694547d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/thanos@sha256:cc09687df6d45e07f683f0a33c9355a437da72cead2b44b90fe86ece32d5a388
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/thanos@sha256:2680c04ca0e9672f8fb2fcdccef87f12ab013ce9e2095770c8254be90fdf14ba
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/thanos@sha256:b9b9e992618d02ed0ba7615fa0a10d9d7955e60b2e9d213e2205ab4e108b0b86
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/thanos@sha256:a0b98db53dbd0ef776751d64aae3f69e9fc3fd7026c73eec379fe3a425a7fc7b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/thanos@sha256:21c4df8ab373724ee26ba569c65c2b6e7b6740db9b0dcb095ec417afa4875a1f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/thanos@sha256:28555f496524a8a6f5350e07b0cf4f36e267d0bc3d2f6c37699e9f1d61100601
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/thanos@sha256:c93a75c3540594e7919ea04e4f671beb67f2b789e44604fa4a8142093a118ab8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/thanos@sha256:278cf1616bd11b33f5b312d42b9bf4e7637ecf4dc74d5592aefd9354f128c8d9