Sign inSign up
Contour

dhi.io/contour

Contour 1.x

CIS
linux/arm64
debian 13
Tags:

1.32, 1.32-debian, 1.32-debian13, 1.32.5, 1.32.5-debian, 1.32.5-debian13

Index digest:

sha256:d8092b1909bd35d89e345641e7edaa3c583f4c431ff99f54767dc7da1974595c

Manifest digest:

sha256:543492fff90c085dee5423edcbd6d5bf64f293e19f229ce876c02558cd2e571a

Size

14.31 MB

Last pushed

22 hours ago

Vulnerabilities

2
8
1
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/contour:1.32

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/contour:1.32 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/contour@sha256:03f01624f6a78823956e90163b310f1514df758944c93818ee596c5aaf4882b5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/contour@sha256:d63f6f7eb11e6e6cbf603717355c5aa1d975071aec4cfb08988177e3441a5ce6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/contour@sha256:dd30f4a408a68a32d7d8cb273770f34c124442413087bec393c3c2508d073f9e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/contour@sha256:c04cfe19e0a6e662f95e1323245c79a1bd23014c639a37fa217ce4ca1dd4ced7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/contour@sha256:e8d57435849e4f5cc186023e061928da4feafbb130589a51791f39e803296517
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/contour@sha256:ec0051af8f9e65e95e25d73e0a94532454f1721e2c4f2e5db26b0d0d8dc2f611
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/contour@sha256:47f75a73fb908beb776ff85ab28f72adff38fda14b08efdbe98ea4505e14b37b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/contour@sha256:6b92c9ed36de67373e73e9c70cae932fd9a114630eddd1092c6944ab85281567
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/contour@sha256:a995cb80b791ae25269257b2e6e9fe716d46dca3a7384d8954e3a60b3a83e3a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/contour@sha256:49da51cd678b9e583057724593e80f2384edea63eda48a4122f15cbbc7107b72
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/contour@sha256:1cfd375213bbba32cef5597f57fb7819fe3d9284572f8de3237dd272593383d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/contour@sha256:4661780c7cc0025dcd295cc64f5baf4b936586be348e59121044bd13ec010f71
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/contour@sha256:a46753b1795f37e97cf09f62fee6e8ef06988b86d0360ddec43899eff6bad541
SPDX SBOMhttps://spdx.dev/Documentdhi.io/contour@sha256:1f8297daa3a3806a5847ad8e3a7a4d50af0df2e287a1f6fd1f7ebba9ab235453