Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.30.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.4-debian-fips-dev, 1.30.4-debian13-fips-dev, 1.30.4-fips-dev

Index digest:

sha256:1d710dcc66320c0d8fae893579cdd611b8399fbe1500b4b5ff75018158fd6bb8

Manifest digest:

sha256:b1a7577f237ac84537a81d4082b7c7baeab3d87f1970f1b3ba684f92a2314af9

Size

27.95 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
1
6

Support

Ends Aug 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:82adc7f98af0c7633d22655f4dcddbff735a8fdfc9591b1bbf5a664b659d8439
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:5602bb4b4227f34e2e71d147e33e290e509d2ec5eafcff5cd2d7a471e046b742
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ztunnel@sha256:25977fab00a2f92a21de3a4b637daa709c5589784609aa5a862bfcce642d5b74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:ac5cf4f4060bebd8a68399906e223050c45c2183addc1f211063d92896d3ba34
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ztunnel@sha256:d5fec40e52583612c468c13927c7f052cabf8ddc5146641dca851c6b29cc7f4c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:f834d984fc820df9d35029ee693165c6a6c7fbceace3d8d1610018d5b53d9ddd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:eda638cdf2bf09225dee1f092be29903a5f4cf962e137d85e262dd7000a330df
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:d7e71202292308d090158d363e03a8177a880112030d815247ddbceddd2c7089
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:a7d433b023a7ca9df26bab64785982225454dbea6523fddb39fd03dc65ad0f3b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:baaf7b54588b05da0ca499b8289a8c2b896adbdc62852e7e16759fcd735790fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:588e8d945e3a2e0b2332913b13d05435f49233cf41bc48bc7f91a28ffa9364d0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:3192bc3709d8b52b2553e7ae12d35327f6f7b43a20f35ec6f4cb2aba6b61ab94
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:ab7368c32c2b70bf7fdae3e7734384d6e952f8e81c506c5fc41e41a9761e5442
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:1543ad42c267e2dc0762ce1ef5cff428bfc1eb7f151497283f3e4fd7a096aee1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:3972db1eab179913220931cc4fd820537a4f0abaffda88638b6faf1c887ea23a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:3d0ad63a7ac263e0516326b0ffb035baf10d2a21813ea9463d6d809c7d401f98
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:19d359966ff60c6f571f7becd4ef09ed3c2d9c344f214f0873c571d86139740b