Sign inSign up
Cilium Hubble Relay

dhi.io/hubble-relay

Hubble Relay 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.2-debian-fips, 1.20.2-debian13-fips, 1.20.2-fips

Index digest:

sha256:90ff65d35e7f12213d6dc5b3381f35dd2589e29903bae1af073df42b7cc963e8

Manifest digest:

sha256:4828c2ea566713162d82efa9480ffb1ecfd30dc63ba3fe8e3f1e0d6606921641

Size

28.14 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/hubble-relay:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/hubble-relay:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/hubble-relay@sha256:ca270be5fe69941561039f8030d3dbdf4626f31b00b78436bb441430ee513e25
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/hubble-relay@sha256:fa6e339d9469e8d697af806b540b9c23593c8419c6d1296cc135483ef54666cd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/hubble-relay@sha256:7df674ab53fa569b0309bb4abb207026fab79332d2facca1f1d133f8d891719d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/hubble-relay@sha256:c71339d8ef4a7fe25e191c590f7a91e72b043205b2067a711b0ac34cc49b3aca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/hubble-relay@sha256:ed19e9a0d652a61942e28761093b15ec3f25f48e5016535579b1480100bdfd82
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/hubble-relay@sha256:c9e78f5fbabdc7a8686b055e6c0735cbf72186419e9ddaf70e85974d62efae97
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/hubble-relay@sha256:b24f24abd3413e64c8ca48968f3faf0dd605f2a218a08f4d397cadea5f853443
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/hubble-relay@sha256:c60b6c85a1449fc8a255c9a3bfb7cf341a72c1f6e56f05a0b0cdeb736aa7d796
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/hubble-relay@sha256:6c02f6fc44249dc243e4e575a09aa259cbcdbf9b0d169e7e97cf2f9a90ed7297
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/hubble-relay@sha256:85249b2f7f536c109ee628ed18f32e94bc6bfca0a9f6eea23126a5c7249b2eea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/hubble-relay@sha256:69246ae0a72c04c905bd30423268bef4ccd3cf3f86ab8b8b731d776df0e85c78
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/hubble-relay@sha256:91392404be815c25fbab4e65e4a6c6c6edad82d4b2e78619d77b508ace5c41e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/hubble-relay@sha256:aff535d024f1a838ce81d99e52740050f796184963f0ed94c74a296504bc9eca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/hubble-relay@sha256:8e435647623d54a7df7bdf2406966312a4dd9e830bca87aa4e659dcf30652c69
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/hubble-relay@sha256:1d3bd74cb3635c2197ad8aa23e0d2ffeaa6839e3f0b3f5f5b1ae8c8bfe53d01a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/hubble-relay@sha256:73c022ff6e49f48927df59f9a543b65f586ca8a077cd9b5820da7869348eae9e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/hubble-relay@sha256:94988fd36ef80ec3374ba927fb435cefbc5214d634d10adaea56865ce21729a2