Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.33-debian-fips-dev, 1.33-debian13-fips-dev, 1.33-fips-dev, 1.33.7-debian-fips-dev, 1.33.7-debian13-fips-dev, 1.33.7-fips-dev

Index digest:

sha256:22aa3e8c8e5b3aaca1df2b2964b747bc0302e508c94150030c2fc1d5196fb11d

Manifest digest:

sha256:637bd606b63a20a33b00bfe48bb404452dedb6842edc582581c30682b3cefeb4

Size

39.47 MB

Last pushed

22 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:9c1158de56c5c1f396a15297641bb4020937179907a990375589421f0cc96aac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:ec7538a20f344ea435eb03bf6ec025b28c6a488caa85ba7dd1f1cb0a143aca9f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:db57e3207e31b7f4eb3d40452464390290acb670962edb082b71453827d0597b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:c867d7ffa0dc60c5affe6e926ac6d22c2da8078ff57c6e6c1939c6f7c64749bc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:876023f882fcb9f0eaad40114e638773bc165aa2412fadff31922a55d12144ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:a31dc163759ce73ba433b796c25e4449001963dfbc3bcdc4009e0c931e6528a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:758dd95d920d86b67673f34ba7904313f5aceebc5626cf76f66b9358f39dada5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:b4708a84c18efe77d461a3d835eb998581b51801e6a42f4e31560a385bd97bf7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:5d5171f7638ffc9686bf48459287c5f1a3100470a8fd9905db087ed01186c8f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:3e503176fbc5234b51fa386cdffe5e03a84fcb58312bccf9abfe2f444010cc80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:d7c6ecfb149b728461c4e5fc73c55258ee45248368302470991a904e1e046fd6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:b8159d5eea0f5eeaee7b862d5fdac23488b58f0d53b0af7f37c91552a67772b9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:f5a2898f3c9628af673c7130c171f1f3511fc786d40dcc5ae0caa1813b611bc6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:cc84e44ea505a806cf18f9d1b44ce1dd017f92d05864bb10593c26f0f69197e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:6ef7e7d51f1c92a5e165528014520c95b059920344eb21452c7b5746c4241d48
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:697b73def3f561d94857aca68fc5fc41e1fede752ef6f4dacda973fc22242358
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:252a68078ef6b1fd3dfbaa97e4193616481d641b0d10e916dcd87b67e4d15e49