Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips-dev, 1.31-debian13-fips-dev, 1.31-fips-dev, 1.31.6-debian-fips-dev, 1.31.6-debian13-fips-dev, 1.31.6-fips-dev

Index digest:

sha256:15886881b9789bdbf51135d4020f9cb31196242434923cb8baedc00cef673d71

Manifest digest:

sha256:4ec2007e5e49ab151df62d00f83d91375e44fd4998437067d9cb72447816a5cc

Size

39.15 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.31-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.31-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:1ede77cde41d76f608a7654f87126fcbcd46aad2fd972c2a993920845bb979ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:ab6fad2f1d40b851d12e7d5e511843715c73f8693b0ecc533d76ca1ee6924d20
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:50ab4df50b45380291ac13c7806bae1ff293c161418cbca8635f285145f1a7bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:d8007f60c0c4ae0ec715d313dba4a3c29420cb7395aa0b13ad0d4e57837390cb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:522b2d34a0539e62298b098c0e2f3a082a061da0fb29acd49a9e4498499e7267
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:0d95722822130404b786580053c991ed988bc268a7c594245a0f230081c5ae69
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:f5d74f2d6e4401be462eb67cba4f70e74e62b32df4102bd82cc513b1b5684fee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:6773b2d211dc0e9f03237a32b8d300cda41ef6356c8045b737d9efcc0ba5d79d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:2a246827c0b8c817cc8cf4c9815ec11260e79e3b2e7cc5decbdc7696113c49e4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:e9fee2c004638abf722c6d98ee145a6a6cf8d7beb017ec79c48d20edd3ee8e23
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:4ffaeddc1b784d10f7ffa30416e3c7975df3e9ae09c72ab826a098383f617190
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:33439e18c23fd25ab153bf6cf47326f951f0865d3b1a98207f5446a85523be7f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:ed783ab2917ccdda7ae0536afb5a9e194a1795492645d5afb26fc14675cfebe8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:3d75f8f739fe5ac9ca4d2738423dd4ebe1037473e497145ab4cb317105999b3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:3ddd376a26b4a68c394557a36093419aeb41253518502df7b8576686a2902dad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:08dd32dd32c6feff99460f11bf30e89aa6add6f32ff86b1d9b2671dcc20cf77f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:9c058509d190ec2f7f361498e2d5d91a67b3aa67137fe3cec405c52e68f54d29