Sign inSign up
Contour

dhi.io/contour

Contour 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.33-debian-dev, 1.33-debian13-dev, 1.33-dev, 1.33.7-debian-dev, 1.33.7-debian13-dev, 1.33.7-dev

Index digest:

sha256:b1d056a2cb85495c3a712125fe19f99b28f6686130d991748c7def9002cc6736

Manifest digest:

sha256:37fdc7712641448a74868fda3e66f8a0ef92b1fe2f6e207142e46c8a9173687b

Size

38.69 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:c9907eb4ca6657fee8a06c1665b8c5c6f180f7a260e40bb2daa4c2911e1fa785
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:ba1ae0ab05f821a05b3945368f3e0b6d18e77f89ab7fd6065f25b96aefe12923
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:7e8d1ef8cd8d70c472b293d51872bb1fdfe79cf519f603cf0d2b28f6f52d100f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:ba1f83d33db4ed5aab7387a514e8eb4598ffa5afe084dc5db86a337837e37882
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:9c8cada6a43df3288eaccda2a7496891b679d4d6d71df98a34dce8318f66e6a7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:bccdee62ad77e36c03757e73335616cbad634b082db2dca855139042028eb1f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:fe4cb8a1187f68676e0863039c890419391d1e0915af10633a92cfe5ec9fe53b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:0feb39058c144186a156dd9350f4e07946c113068500b72bc635557431f3fe79
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:042219ad3e89da97c1dd5267718a23d9d14ab03419e8e7b032ce79020422de73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:7513500e7ee514c358a94135c664687680482bb387bca92070218a89b837487f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:5e033acdedb62ebbbba0fde27b004dc5664b3b1c2fea8889342868e064ec5f12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:9428cc87b96aec74f850a8ba6bf5bad355a35db2c21d87aceeda5db87e0d7ae5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:fa93cdb3ee290489f7af1103fa71e3838ac2ce94863c6b1f35a04c3748d7e898
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:94462645bd0a0dbee44ae9b2a4b591193d55d1bc6f7ab4c75418a7e2a759d0dc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:0df19e6a8ed7ee6805f70c99308f426437be5974856011e83f69e31cf350a51b