Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.31.x

CIS
linux/amd64
debian 13
Tags:

1.31, 1.31-debian, 1.31-debian13, 1.31.1, 1.31.1-debian, 1.31.1-debian13

Index digest:

sha256:ce8a4982f4b94e0bac97534a69a3ec624d2f2492680091d8c82ae47ade6846f6

Manifest digest:

sha256:b48cf69e6ac587b797777332a4533efcda45569e35d4d53b4df3f8f0eeb41eb0

Size

10.75 MB

Last pushed

2 days ago

Vulnerabilities

0
0
2
1
6

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.31

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.31 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:12194788191853de4682ffdf1e23278264a899ac57d783eddf52d6fd9c0fd5e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:8275a0475d4cf7a77d12a40953c322b686be7e26dd4d5d0e7df3b78fc6734391
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:fa528c9662970290612894cd572c66c301f24e4667408ddb2d7a6bb12b2d26f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:e05dad1717098a53873485d76befcb2c25cd6753914748381d570bc240710740
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:4c3d7df7eca38f57acb2f8cf7de69a6255275af1c954272dca75d2667d9787cf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:5f307ef0035a5f2b51f3c1a151b3031ececabb282fc39a210f4758e3665ece23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:42aeab3c030d35e76302537320ed37c2813bf271d8115812a5e969e2b76e9b20
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:199840a848bbb6fc38d864d5870646d51795be1ec34310f54bdba3a03ca990cf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:cfd0beaf5dd92915f965b8b0589347e761aef3972252aa3a433bfdfa066fb6de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:72b7d9358b6c8a51237d759a2a11bbf42fa6d3e3ddc403f407132c302b93422c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:cd6905a1a0fd54968d04fa9fede1b2eb24e376305344c1c91025eb9c998cbacf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:1d7183c871438bebf22955d16325813a9c48dd663f08bb63e35a024185b14fd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:d3e0f00eff3bda54a9389ed9e49cbce06e61199c105e8632b2e4b39556335cbe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:b637777dbeff72585afc3ccfb9ed08cebec2ead7e5194eb55fc951e2a8850a0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:499414130827f17d7999409c369d63fc660ab27994fe6f1c8473d3d404f4245e