Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.32-debian-fips-dev, 1.32-debian13-fips-dev, 1.32-fips-dev, 1.32.5-debian-fips-dev, 1.32.5-debian13-fips-dev, 1.32.5-fips-dev

Index digest:

sha256:b0ec5888e3219e6ab2f26fa9daba253799b6e48f9ffa3dcc4717d736c456c024

Manifest digest:

sha256:1088be70c9cc6f833ed99f5808017b217e46f8091ad0d70d7fa93fdaa6d4daef

Size

39.42 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.32-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.32-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:f14a1ad4f5f01646a9f83d9bbe7a7c242bb141d0f5e9b858b20c66569d81296f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:8bba2c41600bb5135451242d3e2d9a0e8b5fe8577cb8d813082935afa66d3bee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:e6f55beed59560b206e05ba9ee5e6511f745a3fedf728c8dfbdb391f9805e6fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:dec25aa3d0e769e0a811f5d47ac1f50484bc003036c3d9b78da3a95d93de8515
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:c2466f723c221f224b0da9c6b0f1657fef3782b7850ea03295e2d17871821fa9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:8fbd7347a3efc092744b7cacd9e4340f068e6057de458994cbb81bf81aecd54a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:7adac42085db84b542e2737e05e97f43520377d57d4194f752372a6c9c6efbd3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:352f4c2a9bcae0a15bf76662b11026129effee243685f85cc019cd049c8603ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:a6f22c714c22769dccb77e7dca02fb152fab280d08ec12638cc2529fa710f46a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:eb15f599f6311529cc1716a9f5e6aadb6ec962fd31e4205331e6a689e7396488
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:dfc27d28616e5c356ce54ffc16a882022da4053e5023ff890755812dbec9d56c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:eef9d0c5cad0a05c476ff7fc4c59e360e6a7f8c592ea4becb401c093cb553ca1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:b3e8907fd5226cd8c3f834b86ea942c11782500d7310b964b52c81d878ab1697
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:5950c4ba693b419389e1ca7aa19c5a862617702b8e7a8cd512da6bf2cfbfefc0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:9aea2b1b964bb445ccd27927dc333b96d249b4312f587548a80d5abcaef81c69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:db1730e9bfc8bd016d0ce72f8cfe5eafdeaad0919778dca8193eb9e04a5ac49c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:48f4f5525092e15324b96756cf6f71187284b3c17f7dc7b74bce9c372348dd72