Sign inSign up
Kong

dhi.io/kong

Kong 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.9-debian-fips, 3.9-debian13-fips, 3.9-fips, 3.9.3-debian-fips, 3.9.3-debian13-fips, 3.9.3-fips

Index digest:

sha256:5a9d76768cca4642d25b11c87043849bb67aeca5fd9445b6aa23041d1e48b323

Manifest digest:

sha256:da192aaaec84cdae8707ae352f69a3927e536bbae1c7ff123eedfaac2593b88f

Size

73.72 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kong:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kong:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kong@sha256:48e5614b211226dc7eb6502dfe06573ef62e9c8cb0af14ae8b119deb4ac5d0c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kong@sha256:dd2e8d58cba7126b2dda4dc9089c59cd8860d766f2e0f4e5c2a772e7ba9fdf7c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kong@sha256:41b3db813f5a69ee0d88323f9db5c08fc6142337865048492f6c2cccc3fda76e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kong@sha256:e4a84e5e7b5dbb87ac2289f999043dfd2d4eed02412a4e9134f379f432480427
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kong@sha256:dead8722b5b503b26b7b174985b50eedb2193017a2230cb8b1131ac989107029
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kong@sha256:375c80ed7b48127ddce926a1068c552a2e0d9e3ab4a3739739581fa2f73ebf7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kong@sha256:1cdc70688a9a93d4ea3d746c6a01c0a17580490c7bf6343c5089c54bc8eb8576
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kong@sha256:a4115cfeeb02bef0314238e507e8f0fd28136b836b1471503527868ee2703af7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kong@sha256:33be4842b1644c79f70c6be3a6858a37bef94462cc6583d6438b13d4b0ba1132
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kong@sha256:9a564efe54805eae828f56a1111a703b5026b3115041276acb904aeee8d9ba22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kong@sha256:81cc7ab729959bdca14113445377ded21169609fcb45f5de48fa3dea0e01d75a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kong@sha256:62337498c4e9024aa0631739675dd6a6cf3b36bd9eb738c9ede5f214e4440fbb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kong@sha256:da356274374c10f9fc39fe258d4de2ab1fc1e1aef17da5486faf9ca9ebe93a69
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kong@sha256:50d6b81a6e26aeb1ee64d9a9086f1752b80798ea806215e20129f2d937570061
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kong@sha256:4489a5e7775680fc3447865495417f3bcc9e930929956b81e35915e8335ec26c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kong@sha256:47a41c985f10303a30d6e1cf2a68967869a5e15c891c8c27a63cccd237b72d18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kong@sha256:308298a64e2f87346150b18c0c247f798434d7666777773ba3c7166b55ae53ed