dhi.io/ztunnel
1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.4-debian-fips-dev, 1.30.4-debian13-fips-dev, 1.30.4-fips-dev
sha256:1e2cd090f16b66f7a87d2b3188a6dcf1345e4076d230652a809b89ad9589b0b1
Manifest digest:sha256:fade0c90369fec8b59517a98fc175214c9d6f88fc9f588fd789afee71cc8e85b
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.30-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:a5bd4a15fb5fb650b883a34213d1d6ba3f34a7acd2a7f49e880f6f224b196244 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:c6ea4a2ae5dc1f6396674f4369ac4676327dea3a0cfee5d631c15c21afdfcf5f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ztunnel@sha256:c87b3931fd781f89bffee68391bf96d8d637268caa576849758c313ba9e760f7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:4a3f0bf8cd0ada8e7153e8a36d40704cb4cccd845dfe5b92b0ac77073da2568e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ztunnel@sha256:6f912affd07fd7b8bc1d082faa47c3938c29f79a7451b8030ba47105dd3b5029 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:558926048b75cc4c2abb15ad5c1924a8b90992812d8b35508f0fff7dfdb888eb |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:67fcf129b38eec79e0180eed905c0d483bffdc1d60e3f88aa0e0ad32a0d265c1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:ebe3d7f5688427d32ec9fd52967e32b0a62e961c9c523f55d50a7ed72e4a4a56 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:30f5424566793e0108ca073ab269194f7bd8069ca89c6e066fa5db0f8ac9d08d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:4c5bc2dab04b8c86dfceb228df23ce86f1d722cb1858e0dfbfaa6feb38a91525 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:12811a45c953220e8a28d28a1bb7c845860793d7a63e130fd405682bb8d2fbfa |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:667f9e3b4ddb2f32d2060715628822c8f97be6037658a62990cb04712356bb99 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:5f29164cb8b41939f7b3d3b1c0542a08e86fefe55e4ec566b7d43fee8f50e4d6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:fdefb96b776acc795420804222acfc23faa6ddb6e72a2a5090e111e02f8e32ef |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:3d525ff81bd4c67ed8af3974e248164b0a20440b1f0ab141d3d5d2a549291cee |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:f5b5fe621ccb7a73439164d34354728a851374051e3e6a58a61d369c4f8d0b5b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:90bd52d2d0fe0531cf72933dea4654187206e62ee99db9fe70144dc3f9a3918a |