dhi.io/istioctl
1, 1-debian, 1-debian13, 1.31, 1.31-debian, 1.31-debian13, 1.31.0, 1.31.0-debian, 1.31.0-debian13
sha256:b0fe147732e50b7a8306b772af8208ee4d7c1f1e44fb05044dd1058add9f1b55
Manifest digest:sha256:ff2ec1f999281e1debc903bf1ca65d0ada6163a2ed1aad48bc16de225736aeda
Size
24.79 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/istioctl:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/istioctl:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/istioctl@sha256:adf6a0a86abeb976b21ead61aaa4407f33c1cf9cdb9359eff7633c115c2c791e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/istioctl@sha256:8d731b7b3d84f42dc60bcd221eb94123ecdf08e9ac23d04b870b9b08ea378eb6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/istioctl@sha256:cd4b55aa9dbe9eedcf748b0afa7e9d5e337e82d2ee95b7a128a3e2bd00239436 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/istioctl@sha256:a1bc8cf21274b8d28a1ba691b26e09e4a746db6561cc032cea782a70fcf7276b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/istioctl@sha256:20457b296a65cef16735583dcfff4928f782fe84701b6a9312722c180fe59f0c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/istioctl@sha256:1881fd0948f01d8505e688f2e3ab6b28957c2af0bbb2d5b7456a7aa01a98c310 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/istioctl@sha256:c373d9ebde6cb1f974bd10158f403ab2a100176301697127a9da6d0789bb4d77 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/istioctl@sha256:9153de69538cfa7de13291904f93d9062a168048e57f06579440fde9cee80f64 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/istioctl@sha256:6b8c32004e0ebc73088607256bf42467225ddbf79f7794f3f67e2d7e6b2b59b6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/istioctl@sha256:206f8b680bd9184599059031a182e5f03582e71fc05ded425e73874b3d5d3744 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/istioctl@sha256:de6f33b50b2f360c94bdc5935d8a76a8bd71cb4399bc016d4ad2374fc5cc9c87 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/istioctl@sha256:1f21963344c8ce1057d40a1065f90ed2e18955de24a47191a62d55d874cae7b7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/istioctl@sha256:1ecc65740af7dcc2f31b870a5eb4cde5c6521b2571267c417d43e608b2341bbf |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/istioctl@sha256:f437e4dc9ce06b5938b92d282b79f0579b46e1d751072b12dbb8a8e4f20bb4fc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/istioctl@sha256:5fc8bde8959ab5f5d159fe30bd0e14505b943b627ea0c4b3c6ea542b208f59a0 |