dhi.io/ztunnel
1.29-debian-fips, 1.29-debian13-fips, 1.29-fips, 1.29.8-debian-fips, 1.29.8-debian13-fips, 1.29.8-fips
sha256:9b5abf6842367d9a1a4be730e784ff780c0edc3b18f2094f3f68b6ed4257f658
Manifest digest:sha256:e303c15d0cdbf5c7c013972eaa05b098b79becce09cbff51b1ff6a7ae316146f
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.29-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.29-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:dfe6a623a61a5577b41b918015390fbb21711caee53f36215774e8208954aad3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:65fa5d93c87081e55ba1abc31962b6d20048e18cac2a975f5673fcdde3095d17 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ztunnel@sha256:4abcfa86dadb0dfc0ddd44c68600034cb5d0d9ce852436382623061820bf5781 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:9017c53b42be7a7e676ed96c301d0945fb62678b6662607253a5f8dfed109cd7 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ztunnel@sha256:126f64801ed75868bb5fe4f1f5cd0d290ccf0d9632a12972752fd21904a0db4c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:4ebf0161a1b634405745b7bcfb8694cf4effe5966559c36dd188f7e58830be5b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:ff4d3681b71e985d5cf056f6e32b47a772669391142647c05c07e6d965a8b0ff |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:5a30a6af2c7f75602b6f702435476833ac96c277da9ffb8a63bbafc39b8e2290 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:ceda5d3acde5796960b3fbb6ca67263675798c252607a2527735c9b16205706b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:5f836789810e575eaa09b0ea0f3d5695b30135499dc96e5cf1bb2601c46b0f89 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:d9078ef8c5f8553ecfb28fe06e0b925ba58fa318bedf1d2855da978482d0053f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:8beb0ddf58151cb370b2cb8d57854aa9823dff299a3a18fb8616d0251fe4674a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:c29cb05a1477ecc28b1417e56bfce25a45a276f9f12830278755b2285575d5db |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:583edbd190430be4ec47be1496df0279d56d5bb7fae78201e1d9759bbf9f4363 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:f2a7166fb62a7bbe7e564e24da8f21fc2ffcbe44ff450157e6954ef3e2abb920 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:efa6879fc7d7defc639652a47946a38f4f3e026cb8b3d7b1549bc7485161bcae |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:2697ec1a3af7712c20e3126abf33010d5206094aeefc93057cb85a109128f762 |