dhi.io/ztunnel
1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.7-debian-fips-dev, 1.29.7-debian13-fips-dev, 1.29.7-fips-dev
sha256:b6cd496d50225247c52e68b0b64d859ef86150527959fb617717e80f4cc97d45
Manifest digest:sha256:a4d1732b9251cfb20430e2a2629b2a888c770f13086d4fdcaba84b17b384cd10
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.29-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:7ac1244ce8115d3712a1b654859e8b9b094140cf075bc0f56e5d9ffcc11cd917 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:72bb0a3b31f4b8aa408e80e6963eb3e49bff115b0379edf8002045afa8027da0 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ztunnel@sha256:41f21c73a6a93a81b0cb8073d66793d6944ac2f0396007d927df6f4f2c5e298f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:1b1b2b2c5222a2097c2fe613adc5d287be6b507647437d9dd14ed27d95618f66 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ztunnel@sha256:4d272444f6f62dc81a02b1644ba5019dce4cecd1b87defce43a549ee936da68c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:fba4a3fd3f0d51603099506409e039ed1b3eaa3c169a0eeebd2a686afc1f6d24 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:1c65df069c4973e119e51f46510e317505c5a26a2f244c46c7b23713725cc8d3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:49794b9b7afb1136148e6538e17b1686af3fe5501fe9536bb053cca6bf171e56 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:4c260387e16d170898369e41da3f1f4d34159657efb15d555edc7b94bf5669eb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:31f71ef67b9b27e0e279bb2543011e9ebe3799d7e28750c92254ea3f39693494 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:3a32a18343a797ab1182b63ccafcd796f0a080945eba2e54f85ef4e8c98b080b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:a6046fadddda9a4ee7479f90936b5070a12756b4eaa72688da09073c2c05808f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:c593c00f83be422b835440c100918bec8f56a57081d99c02e05ac39f3f04300b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:9e2e1d5257f7db39eb71e1793104785ebc1eafdbfacf70e97b4fec1158711cd2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:55ed36fb3f4c099b53d09563edf4f2612ebae204c15f1d5742ca0e26f65c2bc2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:d44f4cf75e3aedb0dad46a00dac536fa37e656f07894629812f48fa4597cf8f3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:c8d391a0d5e481147c7ca37b68f6794fb524d8806cfba9e27df3925fd6027976 |