Sign inSign up
Istioctl

dhi.io/istioctl

istioctl 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.5-debian-dev, 1.30.5-debian13-dev, 1.30.5-dev

Index digest:

sha256:7046f48aabb64f9b2c3a572bed7f5adfd6f171655244a1e63c1b097351a82371

Manifest digest:

sha256:331046bef27d5e9479ff61a56b9c38ec9b08f1cca714eb02eb5377b47cb8a25b

Size

72.06 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istioctl:1.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istioctl:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istioctl@sha256:9515e325ac8bc3483719051b1f361c7016cb2cd23fae96a71c9409b1fd2c83e8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istioctl@sha256:e6782142cc99c82af9787dee3ed1f09fdfdfe6eed0bfe829820628e3958a680b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istioctl@sha256:9cbdb49dc4fea927cc2502aa30be2def7ae75cd2a3d2e6d4f88963149118b9d0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istioctl@sha256:b0c4d38686b7b83418f1de2646bdcc09f3b0204133dc3bbf34f32eea2ed383ca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istioctl@sha256:698507364d38b580be875c9c00260a5caf03c0d300d44e87d2116bcf648321d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istioctl@sha256:3a991eb91f5710d7c20364b06262d494482d6d806cc8e60b11f33bf8cbe9fd37
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istioctl@sha256:4b22c6225d518e5f15cc3d9334c33e306a1fd096632c48597f51aa2034c92a3a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istioctl@sha256:be07b0fed64ac9b9d66e970096f21c0fda7453a317d4381f0d5826e9ff136fbd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istioctl@sha256:e502e2de82e42330c4572ea08d91e1d4fdb8102e064d3a44c75e787cc8678f44
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istioctl@sha256:149e31b3003ca4ef8c84bd6583911cebd8c729a401c24790f63720918e5ac771
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istioctl@sha256:8c96759cbf8bc728dd34b9f2423ccb3241fdcd708657a4487fd6bfd30fa4d40a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istioctl@sha256:28199a0fad5cc7263073b6a18cb157af40a570af21ce55fc7db9de5db376dd6a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istioctl@sha256:95ef78f5d65db2ae9e88037eed2caf688f37495b4630430d354d8530fcd964a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istioctl@sha256:191f86dc62e05b22747c29b184207ad687ff719e05484c81f0e4f6aeaae13b10
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istioctl@sha256:765cb508ac794f763f30e08e5d5cd82e37d5f287fd523057ec87e0695e776d89