dhi.io/ztunnel
1.30, 1.30-debian, 1.30-debian13, 1.30.5, 1.30.5-debian, 1.30.5-debian13
sha256:65c431f28d63c48bf14a2288733a763f1776807169ba20c3aad5f8c4fc9db029
Manifest digest:sha256:beee6213caa05570b33975d8f4ee85c10ca54aada9d8e84a6e5b2d68e30bff03
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.302. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.30 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:a7ede6d3e9bfcc16cbf9ca6aea4b0eeb9e10e01a274a3cd2669efce634380491 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:dfd6b37da85e5eba9f0c13e63f6474b33e848052350547c71837aa9f1691ff33 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:00f1d0339327955c895a584976f8a00c43de03f187d63420bae9bcd906dd417e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:6fa15845713c04d3ad673d8732ea31f1078945af41ffe5c8a51bb67891805f5b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:2934fe8df4b334620bcd545f5eebf7e63148c983d0032a42251ec7a8828313c8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:8f73adab6dc5e8a575615b58b3c103817dafc0cb241aec392e1672c62a3f372a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:30bccb34af453590edbc308d14701efc6200841d895c5a75d4e94a076cd876f6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:3073cc2351ceb9dccb5e73901e428286b878f519bc5462a381cf038e95171ac6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:f9a8075d7ebdc41ed394957d6703ca3d40a2f8ffa3e0e815be319ac8152eab0a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:710e24c34446d3a914166dd47e05f9614b44c6f516b09ea9663fc344af7adb7c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:68c18b388b3b280e324f949fbdf6cc2546dce94e7d5a34010846a3cd64cc7241 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:d41b723ee4e0ff64b6a7b637ebce75cff9bf7ad275389afde2fd254b8af4f8aa |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:dc290b594a84aee708c73245eb649d15513bb99ecdb696d75b04ef113b706d1c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:144bb3585aa5fba8327e861f85b7fc8b9454e48ae17cd02d050d11b05b2d8fdd |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:2f55be2dfb8cef90b1cc3d4022c7c3e04fa67103b50031cc2f821f09e9f0092c |