dhi.io/hubble-relay
1-debian-fips, 1-debian13-fips, 1-fips, 1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.2-debian-fips, 1.20.2-debian13-fips, 1.20.2-fips
sha256:df7566811f12c4e74e2903b80b1800cad0d8ed717949f617ff879988e5b2cce4
Manifest digest:sha256:d7506d3fedeba96c5fefb2d28b52e1d2c08e79cf27e95e0fd29e3e16a0ea3a72
Size
28.14 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/hubble-relay:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/hubble-relay:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/hubble-relay@sha256:5cea51838296d8085d033fadd93d1293930e3679489e8b6ecc3439a2fb56c3c1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/hubble-relay@sha256:c9bf37e74376611052489dda008a8eb2aff4ac1d56cfc873702341d61c35b566 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/hubble-relay@sha256:47456d22a8e793bda40c51651a21de399d5603ba20779d8bbd1fd8045f78d894 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/hubble-relay@sha256:d3ef4e0574c521cbd49c81775f5e37e8fece121a288acae33f894f8181bc450b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/hubble-relay@sha256:b4269b27db122db29905f17f08e76905462fc15bd17a6aa43d2380692040779a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/hubble-relay@sha256:38959d02a69bcc3843d388b7a45910e9df25753d65edd7116758b6cf379f91a3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/hubble-relay@sha256:1857ed5d8f629764bd5bcd286f6bd3b0d1528190da6956be6079404a8bcff054 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/hubble-relay@sha256:00f7d67825c61a2c326c024b5d859c6d30e2cf7a50c20da97f60177f4cb33f57 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/hubble-relay@sha256:85e573e1e4e0231aa5ff577b6abebac4a0abb0d43ac972c9c293c38d4189f93d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/hubble-relay@sha256:096600e944774bb1a89b874e2c25303cae499216ffe81b318af4b28a3e7065a7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/hubble-relay@sha256:86339af5684da77e11f4c1ca335bf214b4eea10c65712b09d51bf055221dc725 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/hubble-relay@sha256:df1d38c3478503275c7db65c7b0fff8e9ce497a37f018f185debe1658d4f0027 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/hubble-relay@sha256:ca25c6f0dce1b7ffdd016392b966e9ca74b8d18d142eaa944c4c647e43154497 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/hubble-relay@sha256:fbc4ce0fe97c56606ae5442ec8803423ed42f3948ab0018f9a84aa8ec754a942 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/hubble-relay@sha256:19b759ecf5ad77afefb6a7f3be02a7b061764838166c74d8b3784f31c30d8774 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/hubble-relay@sha256:7c2b4345424b587d14e441948d2f6ddff4fef4beefd980482582eef7c094940c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/hubble-relay@sha256:5b0ffa5187b39f7c050b8ab408f32dab00f7e07afa39cbf7c08d4ddb9bdff3d2 |