Sign inSign up
Istio Pilot

dhi.io/istio-pilot

Istio Pilot 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.4-debian-dev, 1.30.4-debian13-dev, 1.30.4-dev

Index digest:

sha256:0b590e666fb95e4ab5bd22609a2167e6e52a777c2bd2cfbfa88de7c03c2d62b9

Manifest digest:

sha256:2a5c9d9850beb59359cf11491678980d6fd1f820c5a2976532301a9b3831ec5d

Size

79.13 MB

Last pushed

24 hours ago

Vulnerabilities

0
3
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istio-pilot:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istio-pilot:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istio-pilot@sha256:9fc114c05890500950b85c1e6f35f4ba089db79f1f53181dc8de20c612fd0af8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istio-pilot@sha256:d1a70fc4d582886f407782fab309e40d2e6ce8207af3b41548450181ec3ed2c1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istio-pilot@sha256:2c2935c38998dc45b9bfbbd6c47cc95c40fb60b8c43afce3f338c6f85b8a6b22
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istio-pilot@sha256:799f42aa968af9874f31621bbc5ee72714a5276ba4b96f5de20da60b6e282215
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istio-pilot@sha256:99987c6a463c37879910ac1f333a332ce1d770b622d85d4c8048abe5dcf4a7c5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istio-pilot@sha256:ac9e1d2d6d34534692935469c109420b75a4afadcb0c87ed11f60313d420c2f3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istio-pilot@sha256:4cf7563e61542d293a9cf13b65a4b95f572baa210c2257a0f05a0ea668b61941
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istio-pilot@sha256:9a3c2159ab812bbd58ec702c517fbc7039e992f71cf7fd3bf71d1ed74736c076
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istio-pilot@sha256:e111a7a8464af0b786454f1b3f1f60c4b594a6d12008081cb2e8a06446644e8b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istio-pilot@sha256:ee96bf469f93bad5b5f712e178b2dc782491606504dcebc6899ad0da791f010e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istio-pilot@sha256:91f51c50e152f892a3b1331427ad3359fe16197fe0d81696b1f2344c950edae9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istio-pilot@sha256:627b6c3a90ec29422fcdb381f6706c60e81c828b091dc44b10ed93bdb45f7cdb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istio-pilot@sha256:f328d04cbe78a975d6775fafac1ae73c3ac69dfb9b16c939fee6e63dd45a688c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istio-pilot@sha256:7a5087377f6c0aebc2c56a714714a7acb91f9356d3555d2b2934874d792cd2b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istio-pilot@sha256:3e558f0b2de9a5e7d780385d6111de67f91b5a3787f98b89f9fcdb808f2bd8a2