Sign inSign up
Contour

dhi.io/contour

Contour 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.31-debian-dev, 1.31-debian13-dev, 1.31-dev, 1.31.6-debian-dev, 1.31.6-debian13-dev, 1.31.6-dev

Index digest:

sha256:f2a8481ccf87850c361f1d8b286386abbe0230cf0b3836196de490ad0ccc576b

Manifest digest:

sha256:dcd96980b1c03883ef886590c54f072242e72f6fa77c5a4f04313f652d42a4e9

Size

38.39 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.31-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.31-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:592839d6534684212095b0418642f2fe6ce9b97ac1b351f0de80a43d1d920270
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:daeceb7828713a33ea1f7ee38aa36a6b05ae8d42cf80d5af418741e5d34b7482
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:03f0486e960c5316af8fb40f3536d6204e948a317743462347cdfdea156bbad2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:c1f8fff424321e82c4c15632823d87073ce5543fe9f5cf6559f5d47afc64c1f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:cda7f359a962d70a81983dbf41ca19d3cc8411d1b8c16577c945c6f60419263e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:1f9bbc4cf5947066d259b60d12b178903ca9024a70ca019396f304323cccd42d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:8a1dc850c0f0dd73cb0abd418184786404df23f178946f7860cd0a629e03faf3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:4031672cf9a34b4c75b2fb2e19f1c5b839a4d24b67081df6a2f148c940b19d8f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:29ba175eb3ec5e6fc11308204aa92ecf0c769c19ad22b13e6bca3f59e7180a08
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:5d64f595ddcde69ca2b51cc1a5a52276cbcc8248c9263f8da3a2c8c14651693a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:604d709e28dae1e6c5b6b1e665f9a28c7d8efec0baa81eebf8fbcab223d75030
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:981d86dda2dc680ea1467f36b793aba099c828a6bce242a11155fbdbfa156627
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:b729ba93c44016a88173c95fb4a4a2debfb1fabdef50d1c5ab3600557a3c2adc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:d29d3c44a3b86dc4be6d818623fcaa4355052f757c7935e18faae1deadef99a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:7ee74a300e1492072a9e8bbe9c361db32cc63918dff62df927c56769ca71f804