Sign inSign up
Istio Pilot

dhi.io/istio-pilot

Istio Pilot 1.29.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.6-debian-fips, 1.29.6-debian13-fips, 1.29.6-fips

Index digest:

sha256:362d4d0c5af39e7b6d2488404167eaca4bf23beb6f2e8d1ad99ff6665b64eeaf

Manifest digest:

sha256:347704b31e83ecbd50ccd5c62d11f3a1ffe34e0dbc205d8b05cf55675ab8df06

Size

34.33 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Ends Oct 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istio-pilot:1.29-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istio-pilot:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istio-pilot@sha256:0b01363cbf998ee9060eba94ce6bc0f9a623ec023d7337860d579eb0ca5cdf3c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istio-pilot@sha256:149c290a577d3a0826a496c742af3716c48a25295415bf93d727590ca9e7855f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/istio-pilot@sha256:05be9a64961aeb0943fc041dafddc502ac3098599d5a088305c4b095ad5c08d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istio-pilot@sha256:49797b64e5a5a573ada8b51f26a213b7e4d027fec655923398666d54d43d2a93
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/istio-pilot@sha256:7cd4c590c4eec67b0aea4e69b49073802b32971603728cf6087eedc7a1b6c1e3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istio-pilot@sha256:c121207306e7b7dbc012901db593e99b51afeb544fb1f272417f02ef63359b8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istio-pilot@sha256:127f64b4ed1f901637672d5ff1ad4caed019f24310294fe60a7359ec3fad7606
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istio-pilot@sha256:e1aff53ca9c525f6017439436e9952331608a122bef6baf8bd95e535af56d75a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istio-pilot@sha256:2e892587b4fb1f02147b28dc070bba07aaaf11dc31b123be70480150af1180a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istio-pilot@sha256:1cccf8924f9c71b70cd64380b9c6d1d4d11a2436c49e6dfca3faa8118c15ebbf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istio-pilot@sha256:bff7728eab7cf55eab9bc1f64613d5f6a58e39f04c3b743033fb5177ccaa028e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istio-pilot@sha256:df2e9889f114df15f9ed81db8cfe25f27eac570695fe79f97aae3b9cd7ea36b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istio-pilot@sha256:7a4a2e8c9b7f7dddc0bfb7498538fdc2e0eae281b0ed26b9edc595d170b06edc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istio-pilot@sha256:7f90814876f59d4c13f5c985bc2812c91bbf184bd11e7fef77eb5c97cdb91ff1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istio-pilot@sha256:e882add3c162d86c8f24c6142f4f83234cbfc3b440a990ae5c3445b54796e19e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istio-pilot@sha256:6179e5dbabccf372a206e40ce15993b4b45ffa0847d54229b98de034bc697053
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istio-pilot@sha256:7538917868866322f458a7318363c761d6f258f687861991677b7419c3f59807