dhi.io/ztunnel
1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.5-debian-fips, 1.30.5-debian13-fips, 1.30.5-fips
sha256:0be8fd74d55409dddf095259632ae5d51787d1a20c855b1a1b5bff3b4b0dac15
Manifest digest:sha256:6736066d5b8ab33fec6b14df1b4dc74235b38ecda06d2de6ef3cded7736372e4
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.30-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.30-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:b3f4243cc6be7b564be548fa49a1c7edc7de85cf67e683e4841826506b3fe56b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:ef5e48e83a3b63b1f30fd3b91d0ac4c4b6abffb94cc1b362db8abd6c59ab995e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ztunnel@sha256:b6fe07abe4a97e72705ed47478e713a8526ad0278f5850d5ff384f4c5e193250 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:f8db7ba70da5ddffc33cc145e83832995c3c856fef1e633070a9b6e940f5b6d8 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ztunnel@sha256:726e6d4deb57f2905f4687c5641e8eaa5e73f2088ea9a375063c1461f0b74469 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:6054d8e1a54ddf1c789e3567dfd0db68319919f61e9ad1a9b2e2efbefd62ed2c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:759a55c69ad0b91325001da94904a76ead5a438f83b934a828b2db203b8aa16a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:1181b368324672c65f5ba53603a18bba8a33a08c25dc5c7bc54c674286a2578a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:a2de161657652259d89ff3271e6d9c2485d897728174efd64ef775d8bf62acaf |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:d2791bfc7f6fa7d383efcaae2b4891498762bf0d4f0f2bba70e45add0b9f536a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:47c4e329882c9a26c631eef1294211fb91e7d580dc63ba2ee243e15308df9857 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:db2b691f7396e915a40cadaa238504d441f24a12935cde72c4631d1108b1c81d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:b63c870c035000f4e8503139529eb765cace4b3eeb41627c776f0b4ec51c2d39 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:bef3909372ad20dd541e2f7f21ec15d6dda7e0220cf830068de32ab96a412245 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:529891073195c6796f44deaf5adcc97fcb51ca5e8786ec115f5f70af6642bd0c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:6dbe3e934632145df3072f82d13e836249fcb8fa4c28ded4e826972bcb9276b5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:421bc8df7fba4cc1ab1619aca8855e136ec4c81348c3cab937b611681bbc4e52 |