Sign inSign up
Jaeger

dhi.io/jaeger

Jaeger 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.21-alpine, 2.21-alpine3.24, 2.21.0-alpine, 2.21.0-alpine3.24

Index digest:

sha256:b2aa03b2f9fb9c6ff71126de5ef9b66f9f408f0e925922d8f1bc86f64d4b19d6

Manifest digest:

sha256:8ae56939574a2bc98fa4f08dd3e43dc9e98d6986d35d1e198b8bcded59945a5d

Size

23.94 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jaeger:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jaeger:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jaeger@sha256:198d3e1600f8f57293c8793d10e674b7f370c3b807d0a3e861907115bd954a91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jaeger@sha256:69b1dbc48246cce1c547ad4a99fe2a81a5d2ff9f2ee037ea9295d7640d312359
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jaeger@sha256:343b0e73bcbfbf79da9a3e298f9a83f5569600c419e9ca70cbf819672f312016
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jaeger@sha256:2365433da91e53e5751ba5d4d48c859bfe14863382bb217e8d68498aa03fe773
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jaeger@sha256:6b6b162619ba2a3184bbed4924abec226dd8edff04d9c6374672380f41a461b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jaeger@sha256:8ee0b62e4d9ee7ee9d578f1ecc16fdd4c088f1767add2c6cc419cf6f2857274d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jaeger@sha256:84baf4034ddb3fbc61de245a1055ae024b0cb2b9896506c6acf66ad756cbf4c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jaeger@sha256:eedcfe5726085efec4a7f11e02037ef9b35ede6ae947609044eea875b6a5f7f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jaeger@sha256:73087273401b98b732ab4ce136c4e9ada35d6e465d92ed9304af4920fc3cabfc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jaeger@sha256:270cd3a52537f46760a43814a4f9ea958712ac3847dc81abc93928807e180f40
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jaeger@sha256:2bd10ff3be112ace18487e9b96d2d283b9b44ed4323917431bf7601ea7c8644f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jaeger@sha256:0bb1256a0d0197ea3aeb470d10d2cb825ffe64419bb721023c4cb40fc098e237
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jaeger@sha256:11c39bbac47b04d21a4f53fa860a267b5dec59877995d1bb97a932ad29beefb4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jaeger@sha256:92bd3b955fcc862d96e9c2168e093b806e82d6e720d956960b29d32406c941b2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jaeger@sha256:c297892ea93a30c2e40e6f4e54f3e8524f2a97e5b4f3ada5ab2b701c975af565