dhi.io/istio-pilot
1-debian-fips, 1-debian13-fips, 1-fips, 1.30-debian-fips, 1.30-debian13-fips, 1.30-fips, 1.30.4-debian-fips, 1.30.4-debian13-fips, 1.30.4-fips
sha256:2b9e90da2443cb0275c040ff450931431ff3c255a63af77f3d2da94888dbbc4c
Manifest digest:sha256:4ca3fca54f3a6aab21dcd9f2a10b28d3cfeef148d72921fdc38363972b5bd8f1
Size
35.53 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/istio-pilot:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/istio-pilot:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/istio-pilot@sha256:73265e7355caffa863ff6e617e8c3bbd1b8941afa75a4a95f1f5eb8758f99ac4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/istio-pilot@sha256:01bfc6b38fc5817e74e9754339346a6c0a3d4780d8a70c53f07e7e5e290370eb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/istio-pilot@sha256:8de42659716b1ad0807e959757b56852e301810f14fec465970fa562e75ae829 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/istio-pilot@sha256:ef3189d670337778b1549b047d280061ca082332c0eb5663651853b93331b13f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/istio-pilot@sha256:391db738d5e9d248197757257ee6ca8696fb034884b93c18a6e7d5be5d56a9be |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/istio-pilot@sha256:b64d0e2b1541d0b5d6d016e822cb88fba370143862017b84693c9e9163ea0676 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/istio-pilot@sha256:cd917fe2603f192bc74c6babbb268b2e6f6ffdbd50153108281c26074f954652 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/istio-pilot@sha256:c8692c7864d536249a25e0bf008d4f0a6ce10700b69ab3749806e28cc903b495 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/istio-pilot@sha256:29ed5a4288446a2994d0ec1abd2b2065e479d2538655ae9dccfa16cf010537f9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/istio-pilot@sha256:204c34723454482ff80292a3b705ecffe285923508c68ae64e0ec8e4e1fa1b7d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/istio-pilot@sha256:d6324f87fcd4c555a181422a8ead9ee319935847148054fdce51982791b49d49 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/istio-pilot@sha256:0c127cb81478bc4e3cef87b737acc0956b9e4d9fec0b517e78aa43f5aa3363a4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/istio-pilot@sha256:fddc0fc9fcaa92d99fc98d5cc7469022b5a19c94424f5c883a689dd9c2b720c5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/istio-pilot@sha256:3c676a10776279ef4007818746cf2fb77e0846dca3df0d14d458780d85292716 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/istio-pilot@sha256:eb0e78edbd8377db6d3db7887abbdf7feb6133cb69606951c9c1b008130044ba |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/istio-pilot@sha256:3d7e594ebc35c4a9db5bd28aac8ba4d657b295dfcf8f07cab370e4e6a2722238 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/istio-pilot@sha256:e02cd9e1306636a0a869ad6bdac43940e3044839c58262f40e43f7a77e161f89 |