dhi.io/frr
10.2-debian-fips, 10.2-debian13-fips, 10.2-fips, 10.2.6-debian-fips, 10.2.6-debian13-fips, 10.2.6-fips
sha256:97fb2419013c64cd7e55ff6fc5220fec93ed755a3240223fbf0a5782e760f0da
Manifest digest:sha256:7ba4276f186da6ab43796834cd8a1aab9bef0a6dee13fdb95dc9c80433437130
Size
73.73 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/frr:10.2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/frr:10.2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/frr@sha256:6d067033e9eda9aa7057e13489ef75ba50638bf3ce3caeb93924a73839625b1e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/frr@sha256:50597009183ea8bc18bb19f063a0fdfe8339fd544c7242f6a0fa80c79a25fd7c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/frr@sha256:9951fca654e1f7e4e4ff34154b00c41102cc330913fff7636f91ea52865a9252 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/frr@sha256:9da7958986e74b3eb2faaf1bbc8905b15b640dc706253eddea4ca92328e47988 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/frr@sha256:3e4269cc4792a14728a73b27cb35f85410f1727a9d3b29f849829b163f22f91f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/frr@sha256:09a4d2968afbea1fd6851d4631c0cd7a20904d9028f7c87e978c5c019c03e286 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/frr@sha256:1fccaa142b211a1b75119b3a91aaa233cdc5bf6542df6c81597f3e218dd35dc5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/frr@sha256:1644eda1bcae4f9edc8b016025eb201fabc87d87394aef56d84913f23aab2922 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/frr@sha256:2def5f9d5197291f0d6d834ab5462cfccbffd571ad26aab254f7cae675f25c0f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/frr@sha256:5ac1bedaee28be1d53c85f3e953b45ce291d13653078c8c1408f8ba2b4969e85 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/frr@sha256:01adf58cafcfd8e6ae017dfef9c5e745172674b39dc2ee4d50d50b27c2ff9250 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/frr@sha256:99d5b3ca06af5e3e4d9d701ceb64f6e3ff3d2e7a183aa281dacaaa5d6f5ef61a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/frr@sha256:d8b74b65ed668e8f759815201b74ddfd69c725c394bcabfb817fb93facb520b3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/frr@sha256:904871fe6824962ec8149f8700727f6556ae47cf4ef57a72b390c39276863a25 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/frr@sha256:c78f1a598f1b39059123a99eed5c4c6b32ab54b32ec7903cf31559bb98db0f48 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/frr@sha256:fe3cad831d74cca3a525ea0192c4ea939cf8e3be4216f9f20e342b688f4e11e5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/frr@sha256:555a5c890524ec28059c7af0985f40ed6871ceb11b4f56aa1dfed18779560975 |