Sign inSign up
Contour

dhi.io/contour

Contour 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.31-debian-dev, 1.31-debian13-dev, 1.31-dev, 1.31.6-debian-dev, 1.31.6-debian13-dev, 1.31.6-dev

Index digest:

sha256:0fd0bcd282c0b7d2b7d24a3824c85d92ce8ed8d29b714e29ae11f8fc876b9bab

Manifest digest:

sha256:84ae5d2e48ce6bf3f79e1a98d457049c8a9bba45e2420c813a12081bc9c92b36

Size

38.38 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.31-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.31-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:badcb8efe50a5ee88b8a00565e421bc34b799df8c4ced8c5ce074ca98a84940e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:6ddb61f967a8ddc34cd07a6779be94830c67084ca5a3330532bbef762b7cb787
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:8285a8cecbb82560120660af42a0f478a915b2a4284638cc3e9dd997ca8e68a9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:c54cb42356bf893055b6a9a28a4efb02743d527558e2c1c6adcedca4b041dcb9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:d251bc760e6e0b7bb90f4e3a355d2a8bb30561ac79738f40d8b446018b5b0328
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:3756db7b63f764c91908ee31ae21292b64bd675be936bbc40fd6cb019d0814c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:59e0c0a17cce4799413ce143c5e282089d01cfd4ab6f6ac2781650cfbdb07c52
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:77b6c571540506b163190e36bfa8d7a8516332545267890a4d7fd609e768f934
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:1ef5da01bb268a327ea49437a85e6a49ccdb9dd79125ac929d2f6b02a35711f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:fdaa0bc9b06ca35316b4c4b3b5960614ec8c605abdd4d176232729e0e8978e3d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:dbb55af64cb5d64104e88ead53821145b0d3358c896248bca7c0520efa15b29b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:95b9721e74d2d07e6c4599cee63b218a1928389393514ab4c93af36c3ae05639
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:e9661a4a511b43c219e472216710ef7103b23268c25899af34021bccd95fa1fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:ac34cc0681f8cf04ce182004f039a1cc1ec5563d9323f7a9491a6668dab9a33e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:3335cb1b4c308e7fc51d7565984934354441e564808940c72292bafbd9d8013b