Sign inSign up
Kong

dhi.io/kong

Kong 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.9-debian-fips, 3.9-debian13-fips, 3.9-fips, 3.9.3-debian-fips, 3.9.3-debian13-fips, 3.9.3-fips

Index digest:

sha256:a6979d96291bc6a2f131003e46d724e9529d34b29d6d0ce8576e53cc8fc5f336

Manifest digest:

sha256:72fe0763b6274f3844dd85054272201703b315e4d0bc4e2169c7c55586994cb7

Size

73.71 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kong:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kong:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kong@sha256:ad153c6b848dcd548f9bd079e60eb7c235230adac90e73e45e5b20d375f6f165
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kong@sha256:d5b2d2125ab7a15755cb3cd60b6e58af41a5ea5a87c80db4ce1e5f762934a93b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kong@sha256:3da19d3823620e2ddd239c68c98e7407448eaf74ff10f8f248d8bff40ec07238
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kong@sha256:716c7798a1efe9a7359676398a48e58dee9db4224377f5d767a5fa2995a8bf70
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kong@sha256:9f8f4f39124689135ef48536dd1c7fab7cec3ec01b0f721293c9e1ea19466f61
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kong@sha256:754f605cdd48f6438da1eff63b95473bd0d8d9daf21413574c82780a033f6fd1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kong@sha256:28e754315c1c1731b31bbc5c66e523e1e3a30b5e3d21cb6e422e84a4d20c1b9a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kong@sha256:3f918e84747a8591e7b4399e78c8b595227360f7f50dba84c5e810561c9f9351
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kong@sha256:915e05101c5eff716670e58028a5b74f3c91d2e80f66b7151226814cb9893fed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kong@sha256:38c4615f851c219f8c4fef09b58ccd34f7f4b77a44462b981f24afd4c94d6979
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kong@sha256:94cc5d5f9b3f3145268a2ae2290f2299d79f68cce567259716d5b54de15caa92
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kong@sha256:4f0cf6a0b6302c485bb1e28118f22ed43297051ad932883ad7ebf9726c6e5e41
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kong@sha256:a8f1bdd1a2f0d895b71731f3005cd01e988976ad2a3347540f1962ed15a449f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kong@sha256:3763665a10d131f5b1d9e93cff12887270469e2e12be02746e3c13ea888df3ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kong@sha256:2fb46abddf305bde87eaa7791371aa8810298dba776defa2665d221780337327
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kong@sha256:37554643af925cdfb979b33c0fd7b8e4df529a035afcd26b9be13040d059dfe4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kong@sha256:d8e67abe53d545fc15d9a93dd35dbde70cd559c320e7397cfe5151a18907f6ac