dhi.io/istio-pilot
1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.8-debian-fips, 1.29.8-debian13-fips, 1.29.8-fips
sha256:d5e6ee5380f9870a42d6eb2b4166c8623323b3c2ef24059204b8d969a767e06a
Manifest digest:sha256:064d467432a2a35e7e384543cad2773d991feb5d1a6f41bd2de76ebf05dcd63e
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/istio-pilot:1.29-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/istio-pilot:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/istio-pilot@sha256:67471c9916df70bbe81f1f03696024f5d70c7c51398b30464724a46b1362996a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/istio-pilot@sha256:dbd4c4af186464a82a448a0510bf0c9271ac89845329ebcd9ead861c92231b6a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/istio-pilot@sha256:ac67b0180c0c96d90af8ffb88a62acd65abe6d2c79d648c6b6db0ba5d8a8d1fd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/istio-pilot@sha256:eb6a88b7d128f4ea7cfc4045007edacaee1dd640a604c2daef546fc0a92c6527 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/istio-pilot@sha256:97d98e631f1cda9aa581650dc664e3722dafef62c7a1f75329e2247e35819327 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/istio-pilot@sha256:80348f8dc82a807187029b39c61edd7eca8cdff638e11b7afa88de6e86be8005 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/istio-pilot@sha256:68709c4b497e420749990a57b697168ae2ec9e0a67b415e31439a47146aee53e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/istio-pilot@sha256:237b674f7ba4f6622fc695080b44d4f9ad78ca48a568dbc67bd1b469b1378966 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/istio-pilot@sha256:d97296bf7c850ddbb8f19709ba4b5253bae8639bc296576210f9e34a1c2de443 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/istio-pilot@sha256:d31ffad79c41ded7e374e4d3c1448c0e7965a57f41ca06c2003c86f08503ae7a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/istio-pilot@sha256:939098c4f4c6a9cb1775c7096a3141d44c554a528ae2fa4034881bda3d706dc7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/istio-pilot@sha256:50c4b43d0ea5b804fec96908949c2b6eb59e50a250aa8dd223d8aef33db4d3d3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/istio-pilot@sha256:21028a44769a058cc5f7aaaa5fb5968f952531c0a7c1d5cd606e19d715fc952b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/istio-pilot@sha256:e43ef6847d14d0a7232bf104cb2a83bab948754ee3b1762ac64560d0480c8f42 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/istio-pilot@sha256:9c1e0189264862a8768f72ae2122cd48f5b6e0f05684a718833b0a2976463614 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/istio-pilot@sha256:dead281f0b92e52d85f521e37f0eb40692003ca5704eef7ee7a689c48d802d88 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/istio-pilot@sha256:b09f65d8193481b9c2c5de9065048a9431b0a824af6c30e7c7eada616b44d5ca |