Sign inSign up
Cilium Hubble Relay

dhi.io/hubble-relay

Hubble Relay 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.2-debian-fips, 1.20.2-debian13-fips, 1.20.2-fips

Index digest:

sha256:df7566811f12c4e74e2903b80b1800cad0d8ed717949f617ff879988e5b2cce4

Manifest digest:

sha256:d7506d3fedeba96c5fefb2d28b52e1d2c08e79cf27e95e0fd29e3e16a0ea3a72

Size

28.14 MB

Last pushed

3 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/hubble-relay:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/hubble-relay:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/hubble-relay@sha256:5cea51838296d8085d033fadd93d1293930e3679489e8b6ecc3439a2fb56c3c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/hubble-relay@sha256:c9bf37e74376611052489dda008a8eb2aff4ac1d56cfc873702341d61c35b566
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/hubble-relay@sha256:47456d22a8e793bda40c51651a21de399d5603ba20779d8bbd1fd8045f78d894
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/hubble-relay@sha256:d3ef4e0574c521cbd49c81775f5e37e8fece121a288acae33f894f8181bc450b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/hubble-relay@sha256:b4269b27db122db29905f17f08e76905462fc15bd17a6aa43d2380692040779a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/hubble-relay@sha256:38959d02a69bcc3843d388b7a45910e9df25753d65edd7116758b6cf379f91a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/hubble-relay@sha256:1857ed5d8f629764bd5bcd286f6bd3b0d1528190da6956be6079404a8bcff054
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/hubble-relay@sha256:00f7d67825c61a2c326c024b5d859c6d30e2cf7a50c20da97f60177f4cb33f57
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/hubble-relay@sha256:85e573e1e4e0231aa5ff577b6abebac4a0abb0d43ac972c9c293c38d4189f93d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/hubble-relay@sha256:096600e944774bb1a89b874e2c25303cae499216ffe81b318af4b28a3e7065a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/hubble-relay@sha256:86339af5684da77e11f4c1ca335bf214b4eea10c65712b09d51bf055221dc725
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/hubble-relay@sha256:df1d38c3478503275c7db65c7b0fff8e9ce497a37f018f185debe1658d4f0027
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/hubble-relay@sha256:ca25c6f0dce1b7ffdd016392b966e9ca74b8d18d142eaa944c4c647e43154497
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/hubble-relay@sha256:fbc4ce0fe97c56606ae5442ec8803423ed42f3948ab0018f9a84aa8ec754a942
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/hubble-relay@sha256:19b759ecf5ad77afefb6a7f3be02a7b061764838166c74d8b3784f31c30d8774
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/hubble-relay@sha256:7c2b4345424b587d14e441948d2f6ddff4fef4beefd980482582eef7c094940c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/hubble-relay@sha256:5b0ffa5187b39f7c050b8ab408f32dab00f7e07afa39cbf7c08d4ddb9bdff3d2