Sign inSign up
Istio Ztunnel

dhi.io/ztunnel

Istio Ztunnel 1.31.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.1-debian-fips, 1.31.1-debian13-fips, 1.31.1-fips

Index digest:

sha256:76bea8c5514bfc17e8fcbc5869970ed07d53542495472e4c94195ea48aa6c1fc

Manifest digest:

sha256:2d93815f2773df75a4668fc92473de11d2b924cc6d4e8c837d10ef92ab673d61

Size

14.79 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
1
0
6

Support

Active until Feb 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/ztunnel:1.31-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/ztunnel:1.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/ztunnel@sha256:b7ac93a87aac766823f1e363170f2626330dd26a61ac8de2fa7d606834b6f975
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/ztunnel@sha256:261010fcf5cfefff737006b4864f747f44e34ff71cd3571140f5cdf64c496c24
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/ztunnel@sha256:cbf43c0180d2b3bb8406a0debe350306fb50138c27c01654b42edf9713314f1a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/ztunnel@sha256:29d935621f2502df04316c3967eabb93f4e4e690759f47992fe6caa6f2633fbf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/ztunnel@sha256:e6645ef08134872adfc924ef68f64dfd6593d53e29a09adcf903c223b38c751d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/ztunnel@sha256:5dd2db60ca09adb648d46aa2ead259641ee28fa67621ed6d680752f2a8126ccd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/ztunnel@sha256:04d469b263572846f137f9fb94a25eaeb68a2056662f1799a6b05f00822b67df
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/ztunnel@sha256:9eb28ccba230d06cbf34d7371af775ba5b59f2280c7e5adabaa0e825cb16ac99
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/ztunnel@sha256:62c92e3a0da3ef22e80f1d0d376a9b1f352c8dcdefeb0d604bf60ad5c0f0abc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/ztunnel@sha256:6c163038a97d67dcd842de2b04ea04e39ae4c6692ddac7412607650931ed20dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/ztunnel@sha256:fa898cafbe6fb21bacbed5c5dbbbfcf7aca71ad43c502793b336b6067503fa70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/ztunnel@sha256:d754161d3bffbe1be63c0e49880b1b756d6a269bf1a4f4751c3d0ea43c23b286
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/ztunnel@sha256:a191214b5803f8f71e271e1ab668504a6949a4d78d9f0813415ebd37f9899f4f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/ztunnel@sha256:7dbc7305219535de15985fa4ff5179fcd5a89ba5f7fab62eb213615b68b74ea9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/ztunnel@sha256:d8c0ce156bc0a4133dfe1d1e7f4f6bbb40333db82cf864bfddfa0aa015daec74
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/ztunnel@sha256:bdb9f97b2de957ce52f276f5bc52764040eb430aa7f486d9e7f5f0bc6c02884b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/ztunnel@sha256:9b0c5f6c27d17f7300fb30ab58f77ceec116c3eec0c962c6959108c79730cfaf