Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.32-debian-fips-dev, 1.32-debian13-fips-dev, 1.32-fips-dev, 1.32.5-debian-fips-dev, 1.32.5-debian13-fips-dev, 1.32.5-fips-dev

Index digest:

sha256:2373d5948809c52de6a9bedaec55fc66dad01b36c04486d9d85c79fd93f1ec4e

Manifest digest:

sha256:34f91eeff2b6951481fa8c7a3894bbc834ed5dcb3bda21096cdf104122c196f1

Size

39.42 MB

Last pushed

8 hours ago

Vulnerabilities

2
8
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.32-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.32-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:c54998b7ee338fef57d20ffbeecdc67215bec520cb52c0c6f0808a84f6ce6ddc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:186ec91b9270f38c61f3d12fe5e1cfa2186c25d87dcc22f48a49ded9bd12900f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:06c5e07aa096635ca59394ad434f6767a3d7bef4d43c3860c6ff97afd7d0c711
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:97fad82b01c084c2426d972302af1a1fbead65b8b505f9eaa63782dca52d5b5a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:a0496d0b38af0f579a1ac0f51a7395bad0ef577b3b74488ef69da221fa2ec346
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:164fe4778eef4c3c5ca23173d9f8e6689965de834beeea10533cdcc911fbb559
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:6ea139e66f1409037ef9da21c7efa36b709a873ff1163ac615e4f3f29d05667f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:ad2440c950772187daeac84927a481624c63c332fd6baeae0a4e7c51393df13f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:1a22fc2af46715cbed9606fa3d27eb2686cd7eb51fcee6d05d9c45eabd1db9f6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:c37e9980ee4d247f4318dacfbe7a5d66752aca0d25723a1cf23d0e3878960647
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:a619f1e7b339039e6196b0a19645e6c4ea8e725c1f5beea8f38f75d911b28ae5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:eba749074c5f8918c5da6aaea126903e8d72fd65ea3e8dde48ec2f283a2d76b9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:3e987f9787fd8b4644f5baa556e30fac26ea630e398e3f23b32360f0af772ca4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:df1850def0b793f8a6c0c30c084bd5f0f2718db53fc8c5f5747ed06bd390e108
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:4c7af113bcad7c3aadd72f92a5d0d939c9879488764e4a1266f585f569c54983
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:172ee61b67ca9b00662c9a1b430c04ae4102d03eb7b45a7cec6c92cf10242ff3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:524d8cae76234fd94673ccd1a0fd46d5674ea07cff5dfef392ed7c52f7864ef2