Sign inSign up
Istioctl

dhi.io/istioctl

istioctl 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.5-debian-dev, 1.30.5-debian13-dev, 1.30.5-dev

Index digest:

sha256:c36758fb25d9d7b51a0bcf7657ecda8b17d4aa9dbfa23d16d24f1ceaca019a82

Manifest digest:

sha256:a5a50f0dd33a1cbb01b119a5eea73afb1529eb58f3c2fab60e1eaaacf79a848b

Size

72.05 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istioctl:1.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istioctl:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istioctl@sha256:865db036858d44c3df9fe0282f8c372ee3324ae9c9cbb145a9e9068a5cd9823f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istioctl@sha256:e0aadf8bb1cbb440827fa5b83ad902fe08c618a79db659e59a6ce428ad336a9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istioctl@sha256:4a6ae458d37feb2fea7ca3a8b71fc706e8de817c560e34ae1b6e81c7f642aa09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istioctl@sha256:247d654bb6bc746e3f950e2b4426663ff597f1d7d5adb4d768fe3df971da3408
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istioctl@sha256:ec843f3e85a134e5bce96cceebdf44f45c928743188fd313dcf81280a7df8efd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istioctl@sha256:efdaacbcbee3a1a9265478eef0963bd61a2d17e6965dcc8466f27ddbd91b1f6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istioctl@sha256:b68679370927e0a5ad6f30ea0b1aa3712a72dfd6c586998bf73d3482a6dc2aad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istioctl@sha256:a8c8dcfe2e80418df359f0a3d8cf858e6ae967c9222768615b903a0e4a20b975
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istioctl@sha256:b64c7fdc7252f673a72077f839da35d5c375dd2522e0aa6f4163232011691b73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istioctl@sha256:d6c7ed824bdbfa3c1f3da4926755bd20c61479c4f311cfb5891601f38a595057
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istioctl@sha256:28b99acde84d9d6080cd3b8abe4595d2c8885fa2fb8a875476aa3164e296b56e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istioctl@sha256:2a484e8a431c8254d88f5c89278df7cd0224c7ff4b2b84024947328275ba299f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istioctl@sha256:e29c25d77bbf09fc4b45d7d4dd8dd720ac444fb5905942c75081f2c4045ac3c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istioctl@sha256:7fa88afbd6c14e69513b9818fad66146ba9e2f5d95bcf3c8a6338b21799ae893
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istioctl@sha256:665858354b98e49efc9366de71e03b990352af7d92cdbb7bc4dd6ba9ebbd1720