Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.31.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips-dev, 1.31-debian13-fips-dev, 1.31-fips-dev, 1.31.0-debian-fips-dev, 1.31.0-debian13-fips-dev, 1.31.0-fips-dev

Index digest:

sha256:703b7e8d1ff1eddbc6564107d4b0155fab87e6a5fcb5d43e7287c310ff6badd0

Manifest digest:

sha256:7f0f7c3e4c37dd54d595b09d96e9afd33ba983d94a9b3b3579955749a19e4324

Size

28.78 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
1
7

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.31-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.31-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:979a2c48bf2b2a13d068f808e0f9b542e273f665a0439d2bbffd2e8e304c39c4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ztunnel@sha256:2d782f94354043bf4c0e44f1988ae24eeb681047b233daea2af9a940ea7e672d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:15b041a913c67926bbed4ea99265001cc01b8b8374bef1f33dc1d0d310bc1590
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ztunnel@sha256:5de0f597db4167759ec33500d23cad93cd849c2c71efe7859d89186f6b4ab03b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:3de48d75c7f78f9137e645560ddaa310d340d0c9d9f41946c28455e272325f8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:6675294a08b951f5dd9c24665b282dba3c071ebfcd257d84c9f68d7377b6bdb3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:4fef184d5aa7292cc6dfcda4559f169af47090c62d8ed8e307dbb423ca5d7207
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:ddb513b05a4096e5f0b2a6f8d07e4fe20da6bd6dcfc2d9870b8bb2098efb02c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:88adba234586df0a64042d544ac0e1f35d02779c39963bae95c59cfd3c89bf5a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:07d090c3e7708846e02f71882f8cd5f280b822a588bed5613b3be1efeafc189c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:25e638fab031c9a139349134729f4f655b3a3352a9a20000640175da6f30b9ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:c31d2f12bdcda26f95f42cf9377949f2eb75f5e7406f96091aea709f02c68850
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:ae6cea7fb7b34c1893071cbe958a2d7a221bad808d796b04f23e987a31fa3ae8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:85b9d4e71ada7a75ad6d39f4e4cf3d3fa0a7167c2b4c69c531372b8647c4f069
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:5beeb418641fd1d0e68cc9cfc3693c65144727bdeaa4ecbb6b353818a1ad21ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:c9a11a42c54a9b52129873345f582be84d0d6c418ed69788736b85786a0e64b2