dhi.io/ztunnel
1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.8-debian-fips, 1.29.8-debian13-fips, 1.29.8-fips
sha256:3ba17fbb23f95f2ef9599e4ea66d7d96cc20405a9abc3c60ced2cb8b8e020fed
Manifest digest:sha256:9b7e54dee5a74244936e9489ad4b777d3e25af017e33b0b9e496a5480e0256d2
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.29-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:8b2ef8dcda14f537128b6ccd7bfcc2c9fb517603787e25d4bed66954f3118d5d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:b339269406e74a932c8fc2313e94ae4c30765a376bab71274af4596c80bfb8b9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ztunnel@sha256:eed441cfa1dac7744372d5bcbd39deb2bec4a5d20d28321510a5e6470c2cda1b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:6a7b3fea2317441a57965071b3757e9f22008fe88ef41e1fbeb30421edb8ad85 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ztunnel@sha256:1e4b5154f44feb712811fb894804f64bd639952929de1adc24007ec16f4407dc |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:c666f71212a5a8e02dfe8a19602ea06e75379a599637363e287a242f00d74b4c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:c3da98e3b11da5208318ac20a39c767a592d0cd28f6f8c6ad665aeae6ec58135 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:a118b8dd4e7b6ee36d23425e33e731900b7a39d37ba093d7f4cf4829678debe5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:f761164566f53aa039f8fa2fc6395b1ce46bcf38c7cfd35a77e38b90c21d8151 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:21de656560572c8253ac383b57c5dcb4faea2da184bf351d8aae4192d3d6603a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:06ec2ced200fe0541d38e58f2ee4537ae20124846dd69e87a77f1834097a94f4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:636ef56b178c95cb0992f977ebe3fad6837406fd4f3f7b586a76a78f22f36a43 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:c4fbd06f9f7d9e57fbc29753f9514e5c237d3a5065f63bf305e3d76548fc913e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:343a2b56ea79e47dddcdf4ea3d34ee3f77034774e7648102fa2bd28b77f27612 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:0bde2f12b85866725fbaa8fbe79e9bbfaf40e4827a9977b3274fdbf3b352f657 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:bba160fac8b9894394497e30c4943a92d5e66400b512e0153321dfe853e3c18c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:09ca53e8308c78100e07a13fd1dabe8197cb536476fefb2a6c54dcb1de5b410c |