Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.30.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev

Index digest:

sha256:334cb2fc5c32c6faa7bd327ecad9684bdeef5484b9b66ba328d89350b1359f24

Manifest digest:

sha256:b171de21489cda5466093f1cec5bac37152b1dcf2db40a406b0d6a6feb31083a

Size

27.99 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
1
1
6

Support

Ends Aug 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:4ff2ab628bbedb9d5602a7ca580d5b4ca4dfd48925a9e5becaff4f2ed461878a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:85c8191bc5d60b673e152b04061f90c965c4f2d5da3644b4549b96669607b3a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ztunnel@sha256:2300611e147360e57b2124c18f914b84e12893efa1cf06776a9113473cf9f77e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:43da16a7396cdd2f381bbb172732b9892009b7485fe09a40dd70cd9362007347
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ztunnel@sha256:c57d9bc7971011ad8ff76c9ae9f16bc462144e3495c8638c784e3f0d2a22ec23
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:68647acc9405f2c0442965605307e0e1cee29be4476ec6d73baed961f052ae12
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:6c2b409abf77b6722b7815911884062785a566d9d4c2237f5ded1d7b36503973
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:d1b4c1c622cd4354b35e437b8c21210026e095271a0942c7c5e5e0c368b04ff7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:65fb51090f84b651a8198c2c9cddd8c5b2a98626f62c441e2f0f6ccc44df8ca0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:050efa4438ef7df49ccbb33081d334b5ef7336b2371fae2158003242539829da
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:6bde3de8cbfabed13e9891a4c29dcf4e63de3c3862d3f002d826123a955f3089
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:b52eef04a2caa108a3b5867e86b0f4aad050ac95f013872ea900b1569a8daf95
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:3150f2c582b3fc35d63461347ae2a427a6afdc7de0b405a617f7f9be80f93530
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:6cea7781170b9400453302d56d5a26b60841154990d8655ff45a8351355ef0f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:08a7b87daed7edef73b3e9dfd747e846643e135f109f568ee686c860b0f2d1d5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:3a45f019120a211376ce51fc30689bd06030e0bcc9bfc31c1847fddf237d3416
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:89653b6d9f78dbb86692e6e47ce23a5342bc039f22d58afa589f303340181519