Sign inSign up
FRRouting

dhi.io/frr

FRRouting 10.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10.3-debian-fips, 10.3-debian13-fips, 10.3-fips, 10.3.4-debian-fips, 10.3.4-debian13-fips, 10.3.4-fips

Index digest:

sha256:5838eddd131a46e7de0481e33ed975d5fa620eb5b4066c66c5443f0cd2113cb4

Manifest digest:

sha256:0253c494b4747cfab2a274390764aeaea5aa797162f04b32e756717dea281aef

Size

74.84 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
3
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/frr:10.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/frr:10.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/frr@sha256:cfe2df6e2e67e97ceb0ed58f000ca6f28913bffef03616a87e1805f3e69bf810
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/frr@sha256:c736da8b40c5aec38885abbdd709e4982fc090b4587547de3b43fd4571b97d9c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/frr@sha256:623dc9f4449d90004f8e0ee2028728b13925c920d484a95e266308e15d456434
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/frr@sha256:1c23c561910fd11013d97cd886f9a2f5e2e7df7151bd2ace38851cf7145758bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/frr@sha256:955b9965ff254d240d3b5836bf9ae4ed38ed2f254648a9217a7452e850004af8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/frr@sha256:c17847bf56c189875b2218f2451e9b381bc84497f0d6cca3dc948e6cb0f69f71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/frr@sha256:0d96d8cd2f49a0dfb1c6d50b5834daf377308dc95535d9e832abb83de074c9f9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/frr@sha256:03243bdc210ba887d3ba7e7462c66fbd981868d9df12bec7d92b481ef1670628
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/frr@sha256:21762949f65222e4f9f90a7756e5a1b07625445b39440dfd5ef1d9aa72f3843d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/frr@sha256:5d2fb0cd14af8a41b669190750b3a826203b028db451ff9c42a208b1731f7086
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/frr@sha256:925fe220151f2b171f6542d94aa7f011d62112de1ed48fc45491d678aa51a572
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/frr@sha256:ef38b73c1af6c838b0c429a5bee76400fe4c104a918980e1418988f5ff171a8d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/frr@sha256:0ee511e3294657ac7f2d3830ef6294b570a005d49adc20ec790f5eeabbd0f2a3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/frr@sha256:1e19d8fe6be4d353e842b7f03d74228ce227d4273982a57e4c5095907f504c19
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/frr@sha256:6cf636f58d25bcf29cec3ee742da2d3c799692393d9fb71027301cd2df1f6824
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/frr@sha256:7bf285dd8862af078a5ef5d1555b063e2b2ba3145163b5b5d092ff4a4d496fee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/frr@sha256:e4715c281c3c8e1b5904d7f63df1b2c025c3402a456a794d087a0e1d639b5559