Sign inSign up
Kong

dhi.io/kong

Kong 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.9, 3.9-debian, 3.9-debian13, 3.9.3, 3.9.3-debian, 3.9.3-debian13

Index digest:

sha256:95af5c7e23cf61402d73103a4508b6c29aaaaa0a12f19f3440dc53ca2cb804a0

Manifest digest:

sha256:1d4c1f7347c2ad850298117ea5480020b24dba8352c691c4c34bff4e4ec1a56d

Size

71.34 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kong:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kong:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kong@sha256:0b87ff2751ae454406df7f13fd512d8921b70e8398eb7e3aa110692fc4bd9a1c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kong@sha256:d26cb4d7b91b90e7b386d2e6cb5f8cc89344afb1713b9dee1123fc9438f4b895
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kong@sha256:088617d8cabb190ada0da8f1c12ad9ee2159209f7dd538faee36ceb5ab259ecb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kong@sha256:49f2b4f2142ed5f5feeb016177ccc10b97bed26d0cf138dbdcac21877241d225
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kong@sha256:dc56218c8bb9524fbc073a10fb43ab681af00281a06a7ebe214cb96af5ab8211
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kong@sha256:e9f27eeae90efe9ba79fed5478464f16b0501a34d3f5343dfdbe6314167c75b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kong@sha256:d63f328b31fd6448e7c1098fe3535a1f8a8612c471fb66ed62fb2d557b5ba079
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kong@sha256:3dbeb10099f5b675ce18a36fc2183234730f52546004a7a0ad6dee7fab2ed9eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kong@sha256:b58f0e7ee63f710d4849100948b24ec9addc2c0e9565e625b027f02961f350d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kong@sha256:8e39fdc224975a482fff3818a6ddec071a407de63163f8e372b0e65c814b6bbd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kong@sha256:bc002c2258e1a876bf0636edc0a08d678dfaae4cad701bce18280ca60a71fd1c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kong@sha256:192749110921b778f7613d28000f2350c6d224aa5d0161efe02e552e853176c7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kong@sha256:408c582290f346deda3a2cc9cf2b5d9d1715bdb85ddef83fa6867f8344a3d401
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kong@sha256:44997e49b7ec23fef956492c308fe3f7068f87b1d18617b1af528e62248ab0f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kong@sha256:5b0a4998101bc6ce4f1cf9fb6fff09ebf39593d98a6b52f9e6ec6f774b39390c