dhi.io/thanos
0-debian-dev, 0-debian13-dev, 0-dev, 0.42-debian-dev, 0.42-debian13-dev, 0.42-dev, 0.42.4-debian-dev, 0.42.4-debian13-dev, 0.42.4-dev
sha256:d750dafe96bfe51dad2e374ea42579aa38a665ea2e0f8cb49bbe687ea78753bd
Manifest digest:sha256:1410f7d210e7d0eb23702b858d9f1fb6a9875c3a59f3fb9e3579bd5a7e5830db
Size
73.04 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/thanos:0-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/thanos:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/thanos@sha256:3e2127aedcce3144361a07755a2474d01c9a4b0b025708801d67f15bc08788d8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/thanos@sha256:166affd8bd7e38b438409a3210f9b43c301778cf9a5d601a1c2a14278ce62afb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/thanos@sha256:352e3831a09d47846206de7f94acb0ac6a2fddc1fbf0aab9817805ffa6c4402b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/thanos@sha256:06bd99c83f612ff668824e8c3df7ad4749448477e7a2f3deaa12f523d213b8c2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/thanos@sha256:d1ecc3e7bd305da8674b818fe0e4875a4d3ac34f7489910bc70da7d75610c0e4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/thanos@sha256:1193e4e059c73dd0f8cafcd61bc32f1b678f1108647595199df7da1a393a3b83 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/thanos@sha256:d838aecc45f963c6badee8b504d1c285ad536f967dfe4daba8be695a78e50c8e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/thanos@sha256:e326c8f8d0b6c6d6b60e38a12633c9b475ffa5e9afd1980eb26617f0e7b9a3f7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/thanos@sha256:854ecc14b195763e62c81edaedf1478ded4b1f49bba78fd96b61e470496d77e4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/thanos@sha256:a8b22423f30b743e2cbcc4025dfcbeabac50b214bf4090b0d6d01c713a225e58 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/thanos@sha256:e734bac632e77e80e8eec66c28546816bb7ea5855a520f26632b14dbc18227b4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/thanos@sha256:bb02dbbaba8fc6cc6772883a40bf7a3dd1a2f215314bd520f7e2648816af0492 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/thanos@sha256:ec52ba46fcdda536a652a38a2e048e8f75f65174cbb774b79b0e07bebe62ce4c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/thanos@sha256:dd08b8535daceb3d3ebd7a30b15e3148243d2a7d1e762faafbb08cfaf9140485 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/thanos@sha256:b56a1c7fdd43eb9851c6f37a61cfaf8889f8e626a49ca3e5226b5dc1011e890c |