dhi.io/ztunnel
1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev
sha256:65059f805a937b9f5e82275c4c34e13f8174541a3123437f487d6d8aa0974cc4
Manifest digest:sha256:efe967d72af8bab6b1a36c9f3bc79c45190cce8a59c2d869bca1da89e1d7b108
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.30-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:88aeb32d5a8c3c826f9575e937532bcfaca63812c22908cedb98844bf8921d7f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:7020f0e5e6c2a553241741b5087484d07c487e78fde9dba892b3e5c8809eabd3 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ztunnel@sha256:7d62c91f1e2e62911a736dba0fcdb8fa7ce94f00abebc6a8e2d793498adc82ee |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:2c114ae9bd7f6fc612f1918fef13e04a3f16915e2655157fec57d8fa0ca8a3e2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ztunnel@sha256:30d60d49efe8374bbca85bc17d3c9b47c8f655dcc0b7303d5f777025b842ceed |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:9597bdfc9dc88458411765aa7c2ff0a87ad5012ad8697ce97da4f6ca280c41ce |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:e2c8330374615afb37e987aa9d26d54b228cd3a32c08ee6182e12b645225a4be |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:98fc2f7d1d65deda895153b1d90935f1f09e6cc3ad907f574dd4004cc0fcbaa7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:c9751450770a07e4b67a985b1cf64ab9b0abde80904a6e64f826aa99f05b78c3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:6e5d981a109d07c799d8985cbfd2f4e952ba6066bd80dc445f51dd21e624013d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:9dd07b620eb3e5205451f6b2cc5c657a8f61b8542d157c925b8f6d68f2596863 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:ad3ad9c4efb752337860c510845d05ca4f2932e3f0cc3e79f6d9be3e0abb0a53 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:9bb9de4ea41d10f833990594a997c0e58677c8385d13f4dba5b873969289c85e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:11a912a5a73be391755e5c259b46cb81a84f44ef69876b6efc1b3c353b6e3794 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:82ed158a74e0a353db14dc252a4500534f41bd413897d466714266cc1c3ca93d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:e1cae91421678c9276b22a36a6f1247dceab8fb127063f62af9c7ef5c6f0f289 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:d691bd6cdcdde923b76d98039df04790dff7a06e6c85d7e8f36aaa482de1d31d |