dhi.io/ztunnel
1.30, 1.30-debian, 1.30-debian13, 1.30.4, 1.30.4-debian, 1.30.4-debian13
sha256:8d1c702f34fc064393765cdea8f40255611178060565bd7860cafca1cd07f4c1
Manifest digest:sha256:358d1b155e44281bdccddfb97de86c3c51ce7bee9d3f6a8e9c4301724ef4df53
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.302. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.30 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:394f2cab74b25d3f5c4f45acb5c7b5c66b210397650a7dd0f874525f5a2a098d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:dcc0f8fd91d5348b395478f394f0ee4df44b3225eeabb17cd0e3a35bc8577ea8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:8a171cb090a6d5f534fd030a5b495d2dfcf684ccacaa699ac2fa7c9202586d54 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:549246a12fb8b98a1e7d23433b831afc15f8a0fd54cc16a7d4f77338237f2e89 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:afae3f4e379b98eb52319206390e521727a66111761ba1d9407c8efd81ca79b3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:c80b4a6fd903c31576c5e3bc46cd85bb64e275e203854202134203445038289e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:6249eff2bfea4014e761d4451a850c9731ca0e74ca66783d16787784eaa8d07e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:d23903cf43b92e83c902521d5704d85414fb9a14ddbffa4e948e0a9a4f39351d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:fabdb71ce59a48f48953112213caf78e58107a66751262086bd820ab3e611b90 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:c47867a761fbe048fee0a3a6b0c3718b26f8de221e0c817bc9c369b516f0d308 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:aec2c99ae1bc0c81817383f43868d50cae0e70f8f7bb155f6f90a99b3246b1ad |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:728dc0fca36c4ca264b4f9fb54c13cb29212e6d1fc6c7db98659a03fba86790a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:7410420063e8e36ce1e752b8e124fe7145a6aad815e0757e2306d2568b50d9ca |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:2af9e5a6d492a5cef18d1f77e5a2919f8badc05e34cf6417cd6a249c6502e2a1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:bea22d48e4734439cd33a1b99b01892c62819aea5e117e58c9ecc4bb8ae623ea |