Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.30.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.4-debian-fips-dev, 1.30.4-debian13-fips-dev, 1.30.4-fips-dev

Index digest:

sha256:f35dc39cad69a0381ec53ebded4295e647d7a0bdfb2f6b1adc823e9b498386cd

Manifest digest:

sha256:8688e3fcf0ab6b04af9241c61786d4eb9f4346762f9f7b849c8ccd7e677ce1e5

Size

27.93 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
1
2
6

Support

Ends Aug 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:d62a925e4e6904ae4f4fd42b2b14d788c03fa0e0ff25fe0b8ba92543bb47471c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:b5daa5f181e611864cb85cd561ba310ef71678183a6241e83c26dd6e6ee89efa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ztunnel@sha256:9c47e8411a26ac72d643cd391c9acca3f476a1fb4d70b0ead85f4d8c89117ec2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:960edcc4b63280481a31d19352564b49fd4d3b0bcc6fcd6ccd7c3c9736c2cd92
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ztunnel@sha256:8f2fffeeb0dffc00de21fae61cbff4fdf877bcd4a20d2c2c6ebcfd021e54be3c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:a95676e3088a9aaefe703cda764f452e68202c3ba46b1dbed152e20dfad0b64c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:b29dd467b1702c39dd8315c5bb23f18e746761c7bebf3238ca01858f995b479c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:b563b2311db01449e73a38293b9b10d69360ae37b7de0998e6689de7475b2eb0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:ce0050f260d502e68fa6b2298dc5f60a541b7b8ee4a93e6e99693c355eca0e60
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:e7cde41e8e228db9d4b70ff2e50c4bfa2a72f267c624c59220dde303c867063c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:60db51f9b2d57278b0d655e59b95ddd54e16d5ae2624514f5775df1d98dc0663
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:60bc22d300a3fe1b607120da13ea8ec0566f80419138e02484e993b2f90c8f21
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:8554c4852647d76e1c6a7f48e99307b860e3508994efa318535151d0f326abe8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:93f9d93a9e9da484a686aebc82b78d1e63406478195c5e1a53111a8d171acd3f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:2f825191af0d4fadc60222a57f97470570c062dc97f403aacf9c90e90ad58d6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:213b61bb357813102626eec9e2e72d1f48018532b84b77d87be26bdc61470051
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:e32f35b659f8241a404a1ef148c8af559ec838dcd6709d67bd349fc1571ac146