Sign inSign up
Contour

dhi.io/contour

Contour 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.33, 1.33-debian, 1.33-debian13, 1.33.7, 1.33.7-debian, 1.33.7-debian13

Index digest:

sha256:860a6cb40c074fb24b0d9e7ed56f458624bc55bbaafa8e147d95752fa7a6a229

Manifest digest:

sha256:deb4a9f1e83514e198286d4bf1184e84099b8da5d9ee2122f6393bd3637dad15

Size

16.08 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:b3d735c8fdb3e081ea39e04626a44b5758cc1ec91f8dd795fdde505e92e79b56
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:dd6e87d0d7cb01a2f947fea97a8b2a4da63e387e8d2bdd982c72f1096c57aa0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:9d96c835e3c9ead92fddfe2e640a6ceca80c64f9a1c71adb291d0fb07318dd58
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:08d29b3cb9627c8cab8cfc71ad7783f7be43b69bdce74f5088e39fcc6089984b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:bb509076fff3075aa9ef5314d3c45e19b7f81d751536814ccac5799b256fd352
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:8b40b2fe870869183e5e8de9d92270e1de06ce9f927b1da28213b946bef04f6f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:a6e584125e819f11c3ba4015cbbd627e2d6f1432c0dc0c8a0fd0ecdb82119281
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:7941986cedd4bbbb8a93e150305a52c383aeea00b3030340faa499cad9c7f85a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:dc313462d99e2628afbd79db1f263c31df09e72da587b32624e108bdef6e9217
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:13506b4b5d5eaa5def10baa5958b04b898d29de63788d58ef4543744cf479582
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:5303a4f2a303298a7e38f11c1f001bf2beecaa1f38ed07b4fa99b9d91d457725
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:a16734ee8ffcb348fa3a41e22a32026ea9ecb650c1e5cf32defa834b71338d0b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:60a5f5a41b40d541908addf8518f69a7835dff15941dabf03624e869189fe881
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:d85ac63933c43ea985d436ca275d5b6d50fbb703536660dc5c5fcab38f6e00f3