Sign inSign up
Cilium Hubble Relay

dhi.io/hubble-relay

Hubble Relay 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.2-debian-fips-dev, 1.20.2-debian13-fips-dev, 1.20.2-fips-dev

Index digest:

sha256:247a04d1e721c2fcc4cb689c420c754f67a9fb9b4aadf6bf667a6bc7032c744b

Manifest digest:

sha256:37f9b28a8d558f9e83d1abb72edb8412e97dbb4a7b965dc4a86229db0cd53072

Size

63.37 MB

Last pushed

13 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/hubble-relay:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/hubble-relay:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/hubble-relay@sha256:5a72f1f65c19933c7b523661ddb68a9e26a081ae0cd13721b609fd9ecbd319a4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/hubble-relay@sha256:7677d705dc8208b864f1e1d2113563679d73081e025fcdfc52dc1bf9cc302e48
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/hubble-relay@sha256:8373a85ae63af1462dd2dc20ddc47e25904577b95fbd94c37716f4f9c8133c1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/hubble-relay@sha256:0cfd789c15f3be6aadab5f3efedfb5e41883d05dc0948d4cc702537cd6400f3b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/hubble-relay@sha256:0d0796e49a2a3d5efc498f251f161ad8020adc52e4e85bb80d4642109eb8814c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/hubble-relay@sha256:94901da52961b897cb5565e936adf66df59a57f4d17339ded8c9f193ea053aab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/hubble-relay@sha256:511f5848019269a87f2b8c6a552a47f82aeff4aac83b50e82fc93440243dfbb5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/hubble-relay@sha256:d69f6f569ce82cf2de2db3c10923289308b7673780604fc2d9d2babe025681fb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/hubble-relay@sha256:a6f1cbd51acfe263884095c3a470f927f05d848e06d6720ec18608e1fa19fc64
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/hubble-relay@sha256:a8fc7934f3838a3743185631b6e634883796da7562d6da7f3fccab718afb5f8b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/hubble-relay@sha256:b83f14a13eb01975bd4a347de2602b624bdc63dfbeea43f5147e7f5bf8cd7c19
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/hubble-relay@sha256:e153c36e13c5e0d3765197a90e3a8269d1f091f1b1c16d48d1c96d0df63fd86a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/hubble-relay@sha256:da8b1014a1b89b1575d8f5a3acd7df94389ea036b8a3cf27f111ea72042d05c7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/hubble-relay@sha256:d70b612d7efebed9b16f5cd30528797a432a89bc52fc63214208184b7d77793c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/hubble-relay@sha256:e128c9e125345278623bf64637c0aac4765d28f7553b096820dad15f6a0beb12
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/hubble-relay@sha256:a05b9491d58a768d90afea91a1e68bec841b0160356d2b0abc443b84beebfc42
SPDX SBOMhttps://spdx.dev/Documentdhi.io/hubble-relay@sha256:47a88ae7adea5877aee210605dba98516ff7d4ab8bf9402798a9a556875e6bfb