Sign inSign up
Cilium Hubble Relay

dhi.io/hubble-relay

Hubble Relay 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.14-debian-dev, 1.18.14-debian13-dev, 1.18.14-dev

Index digest:

sha256:10a77405509a7f34d67917c1192ad4b7ff0f5a40e80c9469660a44aaf3af7b41

Manifest digest:

sha256:2bc078cc37220ea6f2d5611bba074c827e513ab2ef25c0c68c765644a906f4d1

Size

68.10 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/hubble-relay:1.18-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/hubble-relay:1.18-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/hubble-relay@sha256:7f3d42df7217b5b92e2058450d7cdf89870be9fc5671acee039f1782aff60d8a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/hubble-relay@sha256:a94df5ad4aba0b5d99bf1e8a0592f478c636b894d75570d17cb89aa785702093
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/hubble-relay@sha256:648e1395ead8452bdbc035cb9008707a785619604a8d05f9934d7b77a08981f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/hubble-relay@sha256:3c2716b767e23ec8f30e30c2d79330e8b292d64fb38ad7d4730c44fbb726efa0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/hubble-relay@sha256:f36de10dac3ba9ccc41e62fd95c11d885d5014963909a09e64e95384ec9d54f4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/hubble-relay@sha256:cd010b033cb36b2df12fbebab707ac760ba7ebd27542f3e05ee6b9708f6e4bcc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/hubble-relay@sha256:1cc019ae93f426bfd95335680ab430da76cadc54e2ed61b000f47704c3dbc2aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/hubble-relay@sha256:5eae38e8c3baa9ba9d3707caca385c5efb5081277bbf504a84ce9ca4290b25f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/hubble-relay@sha256:18c249416a3e0fda3f5d38a7c0c7439dabb7b393f22704df0efe48441663e228
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/hubble-relay@sha256:bc3b774dac427d7cd15e0bd3680507230825eae949b088bb307a6273b6f62551
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/hubble-relay@sha256:dd7dc8664fb0e809ab94bd76fe7f0b25ef8a8cfcf3a6d51fb1f6c9eabc3d6136
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/hubble-relay@sha256:6e91e6282a8aff9106e86e9ddbfc987fa24bd18b4fb024cce0b139ef2269eae4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/hubble-relay@sha256:4a64521aaefd87876e83b089fb8fb8ded62f5946e6830a0a346183f2879826e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/hubble-relay@sha256:4d9e3472c3bddb5f98f60a2ae34c8574ba645cb3b685e83c0a59416e6698a73a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/hubble-relay@sha256:9226f163b293c8ceb9bc66b56c4217c15587b8b7c0641d864967d7a9229ef9ab