Sign inSign up
FRRouting

dhi.io/frr

FRRouting 10.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10.5-debian-fips, 10.5-debian13-fips, 10.5-fips, 10.5.5-debian-fips, 10.5.5-debian13-fips, 10.5.5-fips

Index digest:

sha256:60e6aa0f90e495d94ed4dc022c86bf44a44432ce7bd80039c8ba102eef8442cf

Manifest digest:

sha256:3b88760e7b1f491e3588b322dc7d1121f9fcf258aa314ce4468ee15af846bfc8

Size

75.33 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
3
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/frr:10.5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/frr:10.5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/frr@sha256:4c083f388a66c3b6ec9d8b475b59696531b48d91573802bad48ee12db8165fa8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/frr@sha256:3e3cff9a8e08299bf1812ec9c02601847b1999b7e985e7a10ee21735f202f75f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/frr@sha256:8927610e0c5b9048804929e58cce2ddd41825c5e416e079d9bfde9baa76b99f9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/frr@sha256:f0f1c173d913d0a74f92668fbbbeeaa14a74dce1849150b364fc333c51a216be
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/frr@sha256:d04e877b1ade99cf805cc9eeb6ce3a34e3e20c4b091832206bbf3e37c43f54a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/frr@sha256:af64b8aa48257b52bf0588dc37bf1072dff45730832ab9148aa38c5ac95cdf5f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/frr@sha256:27644f44790d279ab121a9d6403178356086aefd0c31d8c94585dba385403149
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/frr@sha256:f17d9bb6861992bbbc05d68cbc8ad8d6aa53c3869257f25580fd49710dcf6199
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/frr@sha256:cf5e1a2aab57cdb03ec86a04f1afdc27af56cceb7094d130dc648221ab99d121
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/frr@sha256:493926f55ecbecee03c0668d99e6691cfcc18adbca3a3a33e26680e6e7b5c740
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/frr@sha256:6539ad994b972d53e0ee7ba2c26cc4b75c6c947d140bcdddb9632c4feeaf2529
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/frr@sha256:cd4558a8f84a8f6b73264efe4f5ea690de458d5a001adec2d8906981408c839d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/frr@sha256:5fbbdaf3c3c12fb9a8a077caccceaa73dfd8859eeb964eb6536e28274bd794fa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/frr@sha256:184287796b7eb8ce4228d6c319a4918841e1ee1bf77cba388caa031fe09678e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/frr@sha256:5fe8cc0f07db99d3429c3f539f84c50afc0f2519be582e1b4ccf4e220adb1213
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/frr@sha256:d11d0205237efb625de62f23ce484c6f655d7ba1f847bc2a646c50bdda5de9ed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/frr@sha256:e035dcb476d530fea9d27e056ff5d358cfc11a377311ec7ebac911e5ba098506