Sign inSign up
Istio Pilot

dhi.io/istio-pilot

Istio Pilot 1.31.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.1-debian-fips, 1.31.1-debian13-fips, 1.31.1-fips

Index digest:

sha256:158f15088952be254fc29abff6ffcba526fb027731047dc85bd0c991e8fbacec

Manifest digest:

sha256:4056e81f9a147d7ba1dab4d62e39f30895babef6e80992489a36c7ac7607b464

Size

35.99 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istio-pilot:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istio-pilot:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istio-pilot@sha256:62625f6d3e599e4c1ea6461d23dd7dad90af63c237ffbc6a5f2fc97ddab22202
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istio-pilot@sha256:16d641bfb2b451fa0a45364e0841833b3ccb19c47f0b29e223b1683e1a50f8e9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/istio-pilot@sha256:520445709489fddf8f73a55e6c191bfe6751830ae4658972b2884272bfcd364f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istio-pilot@sha256:6b17be626939d1867814fb2b1ddf59b32d008cc41a96fb877375c757105fd081
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/istio-pilot@sha256:9ac9620b799654ec5e2c2c9d28f87c201988c4f6cf997ef9196d50ac77cf9b6c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istio-pilot@sha256:c66886924988e58307de392c610f0e7e4b0163aa8a087d67fd8367391e9ed590
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istio-pilot@sha256:c811e9cdc513f0bb4117d067b5ea226b59d5b7df9041351b243f0896f3000a21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istio-pilot@sha256:fe2017c8ad7284b844815b5e8e952c586e3bb9f1fd8c264f24eadc438460766d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istio-pilot@sha256:5e98413896402ba13ebbc2e625466638a50d7964d9fd895febd74ca2577e04c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istio-pilot@sha256:1da5a8559667ea0d4c914102310c2f6c7aa3d4d937e25a213184ac3d992ad2db
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istio-pilot@sha256:2ebd0292a8d63d0665e4fe7fe62a8f4621030ef769cb5c21adf60e35537f5ce2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istio-pilot@sha256:3cd49eab577862e9fe9eaa25f7c504038de26f92aa54e7c8ba4ff9427c74e2ef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istio-pilot@sha256:e775c71d3337141ce17db36d15d077da7913200750845df8868722f2fc0d338a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istio-pilot@sha256:7028ef2bb64cab2c929804da5cb1ad2017b20956f9a3fe247d42287bc9117a0d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istio-pilot@sha256:127306521a4c8cab7bd5f690e18b900e097bc30ccc5d2a400b4ce83e38963a61
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istio-pilot@sha256:1e9a427d922c2e6c2d4c1adc1829d91679244766c49333a8a30c5b987589731d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istio-pilot@sha256:dc74d07dd25e8b7b298b656a6728fb934130745269c0523d24101ee690dae321