Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.32-debian-fips-dev, 1.32-debian13-fips-dev, 1.32-fips-dev, 1.32.5-debian-fips-dev, 1.32.5-debian13-fips-dev, 1.32.5-fips-dev

Index digest:

sha256:b4d8eb917eb025e6ba37ad2086df05e67cd7dc9b2234cc6e50313726f916be29

Manifest digest:

sha256:f82ee4171c70288d2932cfe598b6a88fba9b43586c67026203d98287b3496315

Size

39.42 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.32-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.32-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:cb7f483763def4cd17d80f49d3d81693bbdcd14d4a1fd77625ce35d9b32d0ec4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:5d69f42c4bc8348cd79b9da332afa08af8c4b5656b540fa1377eab8280fc82c5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:bb7b42046083211762a5c1e4c64aff9b3e39681b880e17c2158b8d20bed45594
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:1f2a832dc18083382c22237a3c1e0285e44825f1b40a3aab25965a7337daf806
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:27ae989fca536560c7ac8845d276df6633baa2471d5437a694fe0ebd56c77d2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:a0c0c464b985a17f84c73104a6d63dd6f91a4364ebada59786ef35e9ba6224c5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:8646da8f6c1ca66b2b1a34f342882fd10dbc49a6a6dbc26eaa910dfa5e002a2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:1714985201226f08ebb0548fddc4e807dcbb577d5588bd922340dec1aa5c8a23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:a1801b6f2666d6ff07d6484fcdff893ec4468fa5cefee863a91dfbecbcbeddfb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:a77e8da22924bda2ecdccb6ea4251a2c482fd02d0d7c3953562880fff6ed22a0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:9c22a16d69747ba33e839cac783e6e5b02e6bb081ee3941c0998c762b7c7b842
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:069aefa1127ecdc8e5562fad5d857d6e1ddd2e4236a4a5281622736dfe04314e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:200562071d2e227e3436cb330561a6bfbba16f8553e41bbf28c833d5e57a3a91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:34b246b62a40fb6189acc8090ba2dd8f6e0c9150ace24a31a81a4b16896664be
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:a9f8e68b4a92302db7f4fc5b8b3caa885b11be0f9aba2e51dd0714667eb7c56d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:3fdda2acf7f59b14458edba5bff0a8897770b185f96d9a76cf5884369f126e5a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:3e0422e12836edea4c9685189e0fd6b887e43f83bf142f1fe81d6a4d9b57b58a