Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.30.x

CIS
linux/arm64
debian 13
Tags:

1.30, 1.30-debian, 1.30-debian13, 1.30.4, 1.30.4-debian, 1.30.4-debian13

Index digest:

sha256:8d1c702f34fc064393765cdea8f40255611178060565bd7860cafca1cd07f4c1

Manifest digest:

sha256:358d1b155e44281bdccddfb97de86c3c51ce7bee9d3f6a8e9c4301724ef4df53

Size

9.09 MB

Last pushed

5 days ago

Vulnerabilities

0
0
1
0
6

Support

Ends Aug 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.30

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.30 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:394f2cab74b25d3f5c4f45acb5c7b5c66b210397650a7dd0f874525f5a2a098d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:dcc0f8fd91d5348b395478f394f0ee4df44b3225eeabb17cd0e3a35bc8577ea8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:8a171cb090a6d5f534fd030a5b495d2dfcf684ccacaa699ac2fa7c9202586d54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:549246a12fb8b98a1e7d23433b831afc15f8a0fd54cc16a7d4f77338237f2e89
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:afae3f4e379b98eb52319206390e521727a66111761ba1d9407c8efd81ca79b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:c80b4a6fd903c31576c5e3bc46cd85bb64e275e203854202134203445038289e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:6249eff2bfea4014e761d4451a850c9731ca0e74ca66783d16787784eaa8d07e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:d23903cf43b92e83c902521d5704d85414fb9a14ddbffa4e948e0a9a4f39351d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:fabdb71ce59a48f48953112213caf78e58107a66751262086bd820ab3e611b90
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:c47867a761fbe048fee0a3a6b0c3718b26f8de221e0c817bc9c369b516f0d308
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:aec2c99ae1bc0c81817383f43868d50cae0e70f8f7bb155f6f90a99b3246b1ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:728dc0fca36c4ca264b4f9fb54c13cb29212e6d1fc6c7db98659a03fba86790a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:7410420063e8e36ce1e752b8e124fe7145a6aad815e0757e2306d2568b50d9ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:2af9e5a6d492a5cef18d1f77e5a2919f8badc05e34cf6417cd6a249c6502e2a1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:bea22d48e4734439cd33a1b99b01892c62819aea5e117e58c9ecc4bb8ae623ea