Sign inSign up
Contour

dhi.io/contour

Contour 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.32-debian-dev, 1.32-debian13-dev, 1.32-dev, 1.32.5-debian-dev, 1.32.5-debian13-dev, 1.32.5-dev

Index digest:

sha256:b1f558137895c31eeedb92a8b3e85ed83d501858099ce849eee145bc03bab37f

Manifest digest:

sha256:7e7bb04736b6f83bbdb5ed408e22e2879613735737f295c3dc59aafd401cbf48

Size

38.64 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.32-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.32-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:1c8241714d83a72ce1b92b9c45dc2f470912a088a17a913b7ed28497f502bf0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:f5e3814f1d6cade2775f89eeab9542b37aa2449c29988696299587081789ba76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:bf0d929836ed0f4e6fab5b5d27b401edc970b2dc65a0372750bd4c68fb35135f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:197020cf766ae351356df54984491c8ac2f5e92eb2a3f32c20fd94f0aa383b83
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:ec32c35e3a914d8993b60b2745cd4aa65ecdef2d33ca650e1675c5e1dbede6b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:a87aa744bfedd35e1e28d7c726f3fbde5305b3278b4bd56e1727b92650667373
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:a6b3a92824c5f204f28e672938c09c5da97d7119cf0d161df8b24d60ab4fd206
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:bea68a78b2b299801831a0a931af553af5b2f3b511297f701386f2e5ab56521d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:05ba471a794ee0136c1629042188d92649ad66a67d13f3ef27ae871ae2295a9a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:9fa1e6b3892cfb99627c92bdac77e49368540bfb509d0929a47d91dfb58770b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:dcb56571c7adee36fe2acc90e8faee85ed08d08df8a802036587e4a276fa871d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:eb1276b382d49f45768c05f7eb4dc74ae22d0a09ab9523f667718a607bbed858
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:e52c815145e3b421095d46bcd8d8bec8236f267de94998caca45d662b835dcf3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:0c7d3e01340407e1d5449db6fcb37ab045b9097424c4eb141c43898f0d76a0b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:910669906494f88464073833ea404dd98d8a9de833b9329a776eb1362f8ec380