Sign inSign up
Contour

dhi.io/contour

Contour 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.32-debian-fips-dev, 1.32-debian13-fips-dev, 1.32-fips-dev, 1.32.5-debian-fips-dev, 1.32.5-debian13-fips-dev, 1.32.5-fips-dev

Index digest:

sha256:5d4852d7d92286e23d706aec632d52ff65a5468c5793700d8bfe4ec22379cb8c

Manifest digest:

sha256:788d480a1ac075ca7a3b3668f38c7b6c5e45f96abd71fa45c707a58d09850caf

Size

39.41 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.32-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.32-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:8256f65aea4dbf76ce2d1da8bc151b1f139b56cb480f221294500e651f9c386b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:b6be7fd52ac2d81f2adc231afaba37471e2134783074787dea0f303ea035b445
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/contour@sha256:5842691f1140cacbb29da78963264acefeb2b703c637527308fd19b94ac62f02
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:262df4d4c4ec79f043a90d4a90c4f6ea4fd20b41ab582d6108d9bff20cfecb42
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/contour@sha256:125a7bc43d6f655b622a023074c316889a66671fb1e82fa6f58300fc99a5c20a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:02615ba7e686e0c4b2d355f21b4d56ea31ae1d9f68b9f7adc9d0ea86864d38bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/contour@sha256:6c6711ac13c1ef79a8f5075a7b925b73370d9359a4c0f42bfdc8cfcc86adb65b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:dc67d5c8556599e03a10e2ed34bedb3eadcf899e75ab09d9a98dbe69b5dd9f3d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:f7b75687a071fcf91bf0e1a10d6f95e3b7b39e01efd30f2dd0e5d5dfde952144
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:daed41d5e90a959a3d33c419f90e126c48fc1aeede10b84100af5d9afec585da
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:4ea9644d5acf1108e991378f8ce02724fd404ddd9f6009e4c176863421eef586
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:dcd30160a64f2ce7c386296ee9584f828589b933fc8470a697c00799725cd868
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:e9d88aa3f09ec2ebc5a86e6ae3d11ee1de47d945f8a532782740bd1a37ad346e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:aae680eeebad0ebd525207a516e895790996d3eda37799901f487970f2f26a75
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:b77a41de62a94c84af88eb04eb35d1a6e8a5d48b4716c7e1eb49f992ae13a6a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:1f9d6ef43257fbb77a158e771145bf34caf1be1656e1b7aaa30eb2533106a705
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:6beeb4af251922c424f3d05713512f4b14cbe64f34a808389c8286f50161aa12