Sign inSign up
Kong

dhi.io/kong

Kong 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.9, 3.9-debian, 3.9-debian13, 3.9.3, 3.9.3-debian, 3.9.3-debian13

Index digest:

sha256:9013fcb17c9bc0f8f5a1e5381412072426bf30ac8497a29d6845fa2cd3ec35ec

Manifest digest:

sha256:1abb3c3abfffe42f953095a5faea24c3195fd18cd45ef96d773dac8bed835895

Size

71.35 MB

Last pushed

1 day ago

Vulnerabilities

0
3
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kong:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kong:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kong@sha256:29f752dd7a7214c1c7a1c3479e62389c876b1bac05aba7a61f0a41e1283f8f92
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kong@sha256:5caf3f9bedf30499a20e0c5f2cb0e4d20189050abf6877831be87c27b6994f02
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kong@sha256:57f86ae83def2b6f6e30de96bf7d5d7138a9ae6d8452533c3ee726c41ff14e17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kong@sha256:9fa6cb6f08708f8ae018fe46ac6e5f1bcbe8f447f9036a037ed6c650c56557f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kong@sha256:cc4c84e28a9937222b695ac5c5706eb3e6dc07f406a7d222848ee13bceb4d9ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kong@sha256:4f75e3aa5115a868f20a2056d4819f530e3d918ff44b5843c1c14617c32b3612
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kong@sha256:7bd0335edca492ed6d348e3cc02889f437fda6fcc035a8fe8bf8290a066c30ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kong@sha256:3028fdbaaa00877d83813b16e1a03bf4492df2f6b95ecfa7fbaee8baf85af09e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kong@sha256:852545fadebe14fee02386a08d31568dacb72a608bbd97cb717fc68a16caafa9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kong@sha256:5041f483b04a124572dbc73eb66f413d51a57449bdaa41ab087f2761929a85ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kong@sha256:d995f1d3a7501623ff1dee6981f2e3e3d0aab080b0fb845fe23774b5f3b767e3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kong@sha256:1873277d02e5a686d02093be9b2321cea0b26b8bf2a8e0d9ebedf78454762fa9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kong@sha256:9b92f60541e5147674907c03152f98ade57de99095ff2361ea228c8eabd99d94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kong@sha256:cfb3e23697aa7ef6c2e3318ea886656403fff74e0abf98bfd08cf2991dd99e90
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kong@sha256:db36b5f15d6f6e94e9837401663f5c1438fbdb65509594c785658b9f25fbbc3d