Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.31.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.1-debian-fips, 1.31.1-debian13-fips, 1.31.1-fips

Index digest:

sha256:008d3a65212724d24be773b11877c504e16ea5fcc70af3f296db50077485d011

Manifest digest:

sha256:c0f775643caa63ffbe26854d60cfd7d7fec0a6f3dcbde03ea7c89030160ce2d4

Size

14.80 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
6

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.31-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:acbd77d8beb77e8784d5ff0d560569a9ac7cae0a7744be690f56b254e466e8b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:5954fa8f6cb9948703a7d8dd0fc0f270d436f382d40b7b883902173b58cc7a88
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ztunnel@sha256:847611e7c54160eec543d36d73314209d400cdc33e8cfdb348917aa02bdc10c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:69176c705f04c3693e158ee5d664c68016b17f307aa21e95e7f2521e79cf85e0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ztunnel@sha256:77061abd5071fc9f059aa819d9d89ed864d49eeba4a8e0d19a2b26c266f330e5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:f9e6fc01713499eb0dd93b5b57778ee033f916079fa8d84ac6ce7659bb9e60ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:ab0c37cead8096fdc472244c8bfaccc3efc81d18af252efc73af17cf0239141a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:c47be553e9e5dd1fe999e2cc5160e0c820be3cd9b23b937f541d582dcd4ad6a7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:6c14e5416de370af0518b7d298dc8d057db8a06b594d0f67f96644ac6f46d3c8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:843c0bfd6cfcd2057fa99a58c20fbe162d557346ebc9188bd2c56c63b170d164
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:33d7a9a763b879a3db02a235e486b567aa19c727dd1d5dc450f17bc470a9e9ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:9529e76db39774d991820f4b9e977e1b902b8ad5d65f0e7d1c14f498ddc20fd2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:7b47adb778b46e2fb80290637a27253ad8d01a11b7067851a9105282eab3840d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:2c59be1c2e3d47bc11269cda6a82c0a468fe1fd6311bdb060d576a2bbba00dd2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:9cd2c54dc4a3525865cce2c20a7c14cb6e4f6f2cb84748009f23cfe8238b330e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:a39eeeab4cca8a40589de85dbcc4cfe40f52073286e22a9880b914966ca74765
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:7586fef93f297b7db729517660df9f0fa50fb77ddd42f744cead7b4ceeb25ba2