Sign inSign up
FRRouting

dhi.io/frr

FRRouting 10.x (dev)

CIS
linux/amd64
debian 13
Tags:

10.2-debian-dev, 10.2-debian13-dev, 10.2-dev, 10.2.6-debian-dev, 10.2.6-debian13-dev, 10.2.6-dev

Index digest:

sha256:bb37f602dce70dab97b55c45b85aabaed57d362367eca79022f66965ed283def

Manifest digest:

sha256:c7ed9333caca3678ad92663bf4289bed351f32e75f806700300222db335fd535

Size

79.71 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
3
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/frr:10.2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/frr:10.2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/frr@sha256:227f66fc99d66d2f465faffe7f0cb893827ef0a2c5c35a66f54ac5af0dddf649
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/frr@sha256:757676c4f55a54937b37b83f2c674a5fef2af1f2a4530c59a3072bb9dd0a3639
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/frr@sha256:a291fec910d166c7d38e99146dfdd875f9a00828dd41be58652cdbcfecabb74d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/frr@sha256:db79d1665462d347b254f1ba50e754ec765d73829553aa281b23025d2bf84b9f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/frr@sha256:22b0e418ea9e595fb15ecc727e840c5c5fef0291c9229f9f94de5f2aeb421209
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/frr@sha256:29b435d46b7750a4b901db8f775fbceda60444061fbd96a79c43f00409eb467c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/frr@sha256:869f1930b72bb2611a89a24d42622c5766e0e15f0121ca9ca3b75bbbd37ffbeb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/frr@sha256:c1d370df892279980c77343dec4e7166f1f42046fc5e872fcb94b4a185cae1ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/frr@sha256:20add49988d7d8a7cd2d5af902cd58a985c350e915546bafb7c37109adca0693
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/frr@sha256:802fe5705e8987b236f1e38dee7f031ad96b1933010fd58e9bc0621205d9b341
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/frr@sha256:ecc81fc930213771b0fdf75f42337d96279446a0a23a8ebefad5c7cae839de71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/frr@sha256:ff2971a929b5ba764346adbb65eb66190ec670f56c2ee7ef05f5ba7133e81442
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/frr@sha256:9bab30a94b885a01b9ca7f30f3a09ab783315565f27c6aae42d9073f03a0a193
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/frr@sha256:deadbd14e56abe14a73002d9790f8467927a3a9c7db0a840b16fc0f12669fc18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/frr@sha256:c76e64b0be3a79506cd9ef8ccb9c4061ce5f1ef2843f308c5c159749e9a8fed3