dhi.io/istioctl
1.30, 1.30-debian, 1.30-debian13, 1.30.5, 1.30.5-debian, 1.30.5-debian13
sha256:368a373c7d5f94c707738e91caa79e434d848ef28b847eee6235241263fe4a17
Manifest digest:sha256:32fce9a80a4e0cd650cf6523e37bff1cf8d1d15e660ccf04f0fd99072afa3437
Size
24.46 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/istioctl:1.302. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/istioctl:1.30 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/istioctl@sha256:a38fac35270078599087cc6a151e9cfbbdc2acad1b44cabd903a832b0ecfa7a9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/istioctl@sha256:7bb8fe2591ec06d09081f342bb00d27e0207fc1887281f12a8805f48c38ff1ea |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/istioctl@sha256:6c39e9741bfeaf49c0543649f4f0bb30fbff54181237027f25800aa5c16b8e24 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/istioctl@sha256:474207a768c5f0fd36bfa7195da863b24d75c79527ef71163a1a355a3c3638b0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/istioctl@sha256:ff6a0dbd41ee389d7cbd0683417601ddf8312cba9d9ed55eab5a54a87595e3d4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/istioctl@sha256:3ad6e2b18b2f030033df57efc17a1d69b3e47bd2b61bb322e1f71b474983191b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/istioctl@sha256:015ffc18e428f92c1bcb82f1b2903783899ae5fc34e962d3378c39fbfd0dd744 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/istioctl@sha256:4bc745bb22b748094f6409577762419379e85cd18b107fd5911041373add3b71 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/istioctl@sha256:63af60efba2fffdf14befc20d3cbee0ff1f6600cf2313dec7a6ef8fe8233740f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/istioctl@sha256:5de19bc7d85fdeb4afab914ec96a86b88638ff63cd39f5ba74b05c45b79f90f7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/istioctl@sha256:f2b4843e5c1cec5cf063786f67498b7ce640f718f1dc458b207e56843682c83b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/istioctl@sha256:f24e2d844f82421f33e22947068e5174f2e1aadb4d42120a838202acac3fa511 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/istioctl@sha256:b35be551a972b3d41520479e86c92696c0d6edccae9a318c79498bef0977d3f7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/istioctl@sha256:8fa1093a494d9b21fdd8f2590d8ac761aeae48f01e9f8a9d99bcc4279a8dc0af |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/istioctl@sha256:e614004accb13e0c3dc470d369929dcf943fdddcf404c4fc7656fab5dd062055 |