Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.6-debian-fips, 1.31.6-debian13-fips, 1.31.6-fips

Index digest:

sha256:6058c7052b374544159f587c34b776668afc2888df9865a4c379d4d70e2b888b

Manifest digest:

sha256:77bbcee0500096a7e3cf47ed5c840adb6e8b13d44b6e0b423ec7f8711290425f

Size

23.95 MB

Last pushed

4 days ago

Vulnerabilities

0
0
1
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.31-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:2d0c612fd00b40532cc095055f4f00f63a25dd1795bc35b718a3766495ff345b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:d19d8a4710b8c07f77858c3cb2a8f0d7a4aeb56e74fd8e65486ba9914bdff9ae
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:d66d18bd0ce7da50105afc5c2a45a27113ccc9f708ad0d0e2cfa01d0a48adab5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:30c133fbabfa9c354178c1bf0b8ed4a4ca3d7cde1f63de160275343ef143c00c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:47300f148a5df3fb2342c5cf1c59784485d02865edd3e4469516ce0aade4ccb2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:5171d544b4e01fb1817f12736a102454741bab0e8d660f2d505c53c1726b0efc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:4b89fe435219ea8b3d2fc5dee5ef319d36bf5baf3022d802e0b73c65f728b1f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:366e17843869d3dfd44121c39e6cce55f0362f120e086924e9b0b5fb8843aa65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:26567b385ac2844558c2f4dfeb37da804cd932b1fdae7ab96a54430fc338c24a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:38361c0a2d4f1c6a2d848918aa1a7aa354ed632d6f19b06b982f1cc7b1cd7e97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:d19ee399fde5aa689e65d165e270d2cd8348ef079d5608ebcb987f9fb0095f8b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:8d5e7c3589167c2e765ac2b55fa5a39dd01e52910ec546bc8a70405470a0994d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:c6df5b8a0b2e8f8a496e96907d48c0567ab49502eedfd47fa3646e20c936e9bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:3dbcf74ae1bd85abf677c8c79274a31d407f772102abe2b675d488fe45f269cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:c9156dd4098e7daac496ad98aa23f47da10ef253b02b1a4c8244111cb8141bd1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:cf07d178635b6619ed6e90cecb7417ef2c15b47d11a2094af7a44e52bacf89d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:c06ded8bbff2ceabfa0a809fdec94aa06e3fda781158c9047e219978c9324be4