Sign inSign up
FRRouting

dhi.io/frr

FRRouting 10.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10.5-debian-fips, 10.5-debian13-fips, 10.5-fips, 10.5.5-debian-fips, 10.5.5-debian13-fips, 10.5.5-fips

Index digest:

sha256:b30d36f4703b3951bbfef1f34d8c68f8766de16b128ac705fe71a5f6dbf7dfb0

Manifest digest:

sha256:60067dbc8b0bf334e29b5aba1925d27c8fd0d494afb5ca7f0ec6b182dc062d1e

Size

75.34 MB

Last pushed

20 hours ago

Vulnerabilities

0
2
4
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/frr:10.5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/frr:10.5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/frr@sha256:2425a077af3e8e877075d296b83a7d2e8bf240437b9999a5d6bbfb3e8d1ef744
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/frr@sha256:01608b006530fb0297ebe5571a7db151b1d1775afd7e72fa516f29817568f834
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/frr@sha256:ffabedd46bdeeb14b4025e7236a4ff9b00c6418a850658b7803ee1a5bdf56766
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/frr@sha256:2ffd85622719e8eda2c703af43eb81672b1db78d18ca439d7e76c10efa5e80af
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/frr@sha256:ae4fac3d0b071caf11d7a7aa84b9b5b876b0e59c43085950c939209a876a4fcc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/frr@sha256:02a95ce6b2297460ecb5f0e67d24d0f5580ebde189b38a52293d306ef981ce0d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/frr@sha256:ff902bdb45e2dde449449c3f53b3e677c03336be76e0db0d602ec315b7e2992a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/frr@sha256:dced463b3adcba7041ed3e5ec68896498db58b30532b3111f16f820d7cc82181
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/frr@sha256:1ea7b3d75cba881895df753dd46191039dfc1e8cdaf0dfcdb72176b580c045e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/frr@sha256:e74e562ba02ac96d719264176297edb26d8a4c35318af46cec09ecb59c25ae04
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/frr@sha256:56367db462d839697530b33cced0d49e5ff482e14d950b3b5aca5542c7516797
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/frr@sha256:dc1e08cd25e22913b0243be8d94675fab9ad4f43d5cc38e72226c5257527cec0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/frr@sha256:85652cc1178f88031e18ee20af283ccac864bcbc19c42fc99a4ee1fac7bdbe30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/frr@sha256:7c0ff41890575d28ef6aa578db8b51ef30830fa4b57ab84effa06b0141b07376
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/frr@sha256:7285f4e39cac6f2efeede776a6f4b9424ec7ad3c7965c0a9b534ec4292117975
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/frr@sha256:f5a94f99c78f394cb26237c088def4bb5436e0bf84cf2076c6b42acb7a06aa59
SPDX SBOMhttps://spdx.dev/Documentdhi.io/frr@sha256:ae9b6fc7eff46e3af1f215242beeb96954102dd4b2af98bec2130cc0bb398dac