Sign inSign up
Istioctl

dhi.io/istioctl

istioctl 1.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.5-debian-dev, 1.30.5-debian13-dev, 1.30.5-dev

Index digest:

sha256:c8554c5b2aa30987f744f1b5fce9c51fe06cb0093bd55436360a2b67a26f594f

Manifest digest:

sha256:c511306da1fffbe350c73c0612e14f6ffff2fbe064d7be358efc868a5c122549

Size

72.06 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/istioctl:1.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/istioctl:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/istioctl@sha256:8fe9cdeb521e39a6af4fcd0aaef7ea1e796e23aea6810e2f251fc6e37a77ac3b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/istioctl@sha256:c1b822d2733a4c1e18befdae553145b2ec1429da0055cecf65cd0811a974088c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/istioctl@sha256:e25003fa07f86e99942b73a6800719090cd8d1b64f2ceb568bcde2bd8ebe752b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/istioctl@sha256:c7a564d4ed3b2f402180242a810c48b5fbe26074760feec4d5dccba707857ab0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/istioctl@sha256:286a365922c10b5137c49584f96c4d82e23591898e2d05adb5e307242384bf11
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/istioctl@sha256:96e16e57ea500626c4440945ecc533faf8d099c1376a5b54e0f55c9d3f641bfc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/istioctl@sha256:96dac1cf3461fe2829c89159fbfaf787cbcfcc16330138c4d3b241a898702572
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/istioctl@sha256:177e7170c7f4d6961080e465eddd7f4a122c0d82ff00b19efc4c7204f99540a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/istioctl@sha256:d4cc0d7d16288767a53fb5cf6d5274d4871bbd5a2742b5ae8678158f63b7c38a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/istioctl@sha256:543922e353e5960380b85b7bb0e87e1f39aaae66a13e7eee9f91e654b98cf6ca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/istioctl@sha256:9e33dd91932e70d57840b359f414f320fe0551e3b94d732ccde5943d819a3d8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/istioctl@sha256:2d0d45f5fcd80d01c9c5dfc8fe82d3da00d931f5b8254a58e6ce6eb9ed69a594
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/istioctl@sha256:480e68d917fb632455dcb0450eefc29e4eb44743967daaa098b8d8f9cbf2f58b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/istioctl@sha256:d5f175ba58b4dbcd93486eb198d33007d4a161a558e3756eaba93b2e578eb487
SPDX SBOMhttps://spdx.dev/Documentdhi.io/istioctl@sha256:8375ce45a43d4c6215eec2493f9ab2fa2448e377a00f8584dca6c106ad592af3