Sign inSign up
Istioctl

dhi.io/istioctl

istioctl 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.5-debian-dev, 1.30.5-debian13-dev, 1.30.5-dev

Index digest:

sha256:872f7f1af9fe01fd64323c011a63a736f275a190d8e96492b9525a1bf632d4ac

Manifest digest:

sha256:73faee34fafa407701a512fe5b71e44c45f70f7582f2ed4482776f36372a98c4

Size

72.06 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istioctl:1.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istioctl:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istioctl@sha256:083a0bfe20c0cc64985a4ad46918af92d814b6c2baf4d35c8a41eed90516e796
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istioctl@sha256:d8573a02dc64a08c9a034a1dffca5f24d108334b0cee06fecabe2f2e1438d9f6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istioctl@sha256:e318ebbf1f14ae8875f2f9646927252052031c42fba348c3daed3d70d089788c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istioctl@sha256:8f28ff2ffca4a3fa2d6e8985b46e5ef5fa37c878bc688ebeb3d786adbb8a1c11
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istioctl@sha256:b49c3497d9d7ad0a6a383de808ee182b4f0e7001feb03199adfb7fae226905c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istioctl@sha256:917af6bcf140d330e02debd1171ca05ca656704a7a6956cf0f537e12db9e01ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istioctl@sha256:8d6d0f811104d98903646f42747a2060e31b4fb49879d52bcc80edbbb6a5f863
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istioctl@sha256:c9a4a48099c61e958975a042535e430252a92ccf2bf916e31f9cfcdba7888fb6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istioctl@sha256:5e7bde0b18d8d6e3e135c064966d0b68d12428049a577048a96a1e5718838f2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istioctl@sha256:de4d07893f6b3773de98c7aab3e03d9df5f25458ae9f8480d52f48c3da1800fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istioctl@sha256:2f30352bd028852471eba0f6b8c7a7d56d94792da4439e2199cb996f92c70c6a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istioctl@sha256:78a4831ddbe203b802e2d0fa069b2798c52e30b313aeb73677fe6b0ac80d869f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istioctl@sha256:7bf67dac1b1cd9135bed37ca0d2725dcbca983ae22b227be63693d8ece2ad0b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istioctl@sha256:4cc2435b6e836addf936d9c57785806090b5ea088a7dafa919a2b8ce0e5e59fd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istioctl@sha256:e83332e925aed993c88bff5cd69b74005e1322f104108812e93655bbcd56655e