dhi.io/ztunnel
1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.4-debian-dev, 1.30.4-debian13-dev, 1.30.4-dev
sha256:eec86a0740be09a83beec7e3d5203fa24291b86bfee976f7bc6921bdcd6fb34a
Manifest digest:sha256:dd26aebe9600b38a2ef67390af20d73d1668056a374b913f759fa41eed44325d
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ztunnel:1.30-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ztunnel:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ztunnel@sha256:2e0186d4ca5f0e4069d93de1117ebfa101e7dac73156e636272f03e34b4e5b3a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ztunnel@sha256:c2de3762d5c26f9f8befbb75225311ee9bb6a07a529df84d76ef7009a3a0a94b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ztunnel@sha256:a7f6b791572f05b7fd39748ff3c0ab9e87724fc4b617157ee91c66f3ca30eecf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ztunnel@sha256:71c53dcd10235a119abdde0ee4b33d76bfbe30c978f9545b7ca41fbd32d149e3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ztunnel@sha256:05e4249e79d80cf9f785fe3da1c565a8632282f5fdb9d28fcfc7b5f272f53eb6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ztunnel@sha256:370147482ec3b4a7fc54c9ab6d8ef2374ddc08076799b79ce7b76a43de082a6b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ztunnel@sha256:90db3dfbb1c31b6d3c969e8243f83b2140be28d4a1bdd33af8d2b3fb0ecc37b0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ztunnel@sha256:08ee5d4d90a819f1d6f487849df84811f4bf81f07c596b1ebb3b7f6020ffa619 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ztunnel@sha256:0630221f355f396de1bbf98766d41f38595926f0eed73adb2b6ab08faebf443d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ztunnel@sha256:1a43be56c6976f8de9ec37811f66e28792a4117fb9f78503c5682efbe501a49e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ztunnel@sha256:e78d40e00e308d1b81fc0119bb80d5d769fd5e59a386e057fde7c5adc5cb128f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ztunnel@sha256:37e4dbc279ac2a3ea62653a548855cdee15d130b4a26043a2a26fad8a9490461 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ztunnel@sha256:916146526161ba473e15caea2034b436d226297b8a94eaf09c783bb569682795 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ztunnel@sha256:293b4afabcc80a01f3df7df922519f0dd68044b6d12891d275023798470ed632 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ztunnel@sha256:050aa58275608bb0a5ca3cfd2ce6e8404b799ae3987bc902d09ad9435cb90cc9 |