dhi.io/ztunnel
1.29, 1.29-debian, 1.29-debian13, 1.29.7, 1.29.7-debian, 1.29.7-debian13
sha256:0ae5224d92712c5db4ed369f5bd31ec4ad6f3dfdf646235a766af2c1e07b272a
Manifest digest:sha256:ad029ec6e4cda18bb142ca70a5661f22f774faa8831c26588a4af9ca0203674b
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.292. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.29 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:379bffda4789c90704c370e3280cb13a6c8d2fac4d061b4b2831ebd2a14ad3d9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:776f5c442ec61572b25e33cd9c51f67f336cc80709e0a4322685e8b102f48f77 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:596bce2312750233fec095c186ee95a47accf99c5a77b15e2959eb76a75cae63 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:d9b6cae1928a04c56f40fdbb2dbbd8c9b620cfdcc197d39ad0a965c3dc98a391 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:b090341d823c0a33aa90981245e36c6f3d99289622cdab1787ce807c6a2e5fe6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:82ba6f1b49fdab280ab99e25be58f6f7a84ad579a0fa6ea778769d81bf8906b5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:b79f1e7be94ade80b545162828fa318092512ac7ea4b45ed45031a1e7ef5e4c6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:1358c74012d6622d54c0f843cd1499e969ac4d8ec7f00a6b1be6a4fd54fde4f8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:780a0552e79c302569ad09a40eb6d010c89f249792e209520d71c8f58cd2f9c0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:bad0ed3a8096395a4f2e0798313095e7045c4d3f467f8c4d9ce5e75340266320 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:b9db0b674e164ecdc909eabd18ccbc2bea50d79240f9c5f12893cf901ccb3042 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:80c73b7968a6270a7d95576ebc5ce52ae16e2ea5362a227fc8e14ee8c364b3bb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:5c4e75e1739fb0384c31fec626bbaa65be5acf0c6f79f95c0002819ac7820348 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:1a347fdbd2086e8fde25c1dc0d6abc321aae8105dcbce59938368baf0ec710b1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:9959f9163a8f19a7be3a1f68a848090310d0da8fa02c493f06bf65a620ff6dd0 |