Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.6-debian-fips, 1.31.6-debian13-fips, 1.31.6-fips

Index digest:

sha256:854c99d1d82160113ea3138519905faa33c4c4ae1d69bda0360b16bda86fcfef

Manifest digest:

sha256:d36f5366621f821dfe5272c114d424d5a971e95f5c4dd815506e9d60fd0644c2

Size

23.94 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.31-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:052212f0436a957e067ba1a3ad012f74099f6153f041d1b55cdf6c5ecb44fa55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:01fb155a6f1be2c71496ac7640e75ec2546f7279512848046205bb37040c2ae5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:6b33c9ad98865c2b3c1e4bc5a7de800103f2a21214442320ed0877022f78c7ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:8993b7a2b49bdeb3967b05bbc85cd64cf5ad16d5b2ac58097569b86ee2e97882
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:b7711b4201dbd1ced07bb6ef6059a2a4541d951b4e1b767c65e635372c65a36a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:c298db017e6e8a51300d3093a16185ced097fa7e6ae418403a22fb12b8b7d784
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:74beccf7c4ec5c1dcbbb1807fe099bac1e2b80c8c9465528fc074f324dea9082
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:91b712b3d85debdb11a52ab23221782d00b6512fed505911e4a00bb45d25cb6b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:da85764da8118a946fd408645b5406ab47ccfd4704c7bc8810d194dea67b9edf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:75dc3487059c3eca152056d396e7fa730a0ecdb02e6ddfc0f34a3a6d14946e40
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:87c04456762e4c1802a5715c56c44ce1aa75a0c5ee18f13e8f120f2d43daf292
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:22dda6dc39edffa3bb441ac00bdb1d8dc4eba427ff947efc1076f1349b217f0e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:4713c580dd4faa207d38e381225d1b1287ea955352dcf701481dcd0e5f2dd9ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:975eb144b205a7486305e4f8478830278839acecbe3340d86c7f38a72ba1fdb5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:73e903e9eb1990371cd1a67c4b29e636e6a761be439509961bff675ca8ef1773
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:3780d627877cb3a7dcbe9a41da124f4bc84dec197195a96694f79e9b7179290a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:0c12290a988ab08e057d8a732b82fab0321e8ec95f8ae55fa15b2855f88c2f13