Sign inSign up
Kong

dhi.io/kong

Kong 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.9-debian-dev, 3.9-debian13-dev, 3.9-dev, 3.9.3-debian-dev, 3.9.3-debian13-dev, 3.9.3-dev

Index digest:

sha256:5e66c4e71327c3213bd8ff07ff2974a927013951a313041abc9b656a04a9ab66

Manifest digest:

sha256:c8c4dcd7a932fdf73c60ca97998494c70cfefa069ddb85aa4fd692d36a9d49dc

Size

79.38 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kong:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kong:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kong@sha256:11405e973c13c069e45a83ebb365f9e4385bfbcf805e246b1c6e356085a5794c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kong@sha256:3aa334d867d0c9db000660192fee49b0f7cd3ca8c852666683d4a46387431e30
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kong@sha256:8293a4e9507faf3fa01a6df9210315e16eb157c562aa2fc4c0b0bfbdb43b748c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kong@sha256:ad08cded2d15eef9710d2e67771eb7a591568f94fe7ddef492b37ac6ea2d5950
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kong@sha256:3a0cefb188d6362460a2fa144c11c19cacf04a8129c5026108ea88a24d082e32
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kong@sha256:cd6793b2901ff1bf91ee9129255eeb3ae55e6c465b5863571713913cbd3fef6a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kong@sha256:d0256b910ff67e2eb2abd96d1bf803e9da04a570d2246aa15e55b05eb95046b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kong@sha256:ca80d3aed6479381118a101b6ca5d8f0fb29ec9a2b96084ba558cb5b51af962f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kong@sha256:d333db37f2b44985bc37269ca8ac1524de340b6dfde1974b47ef683aae028f3f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kong@sha256:927cc1c34819f9b0656684e2873aff970302ace783f7e2e7741fc78cf11f18ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kong@sha256:1b54e5fcd79e7a30b94beb06996b49dadb554885c9f44c9ac529d40d096019d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kong@sha256:53caa7c4ae17b6ebc17768fcc1b464be4cca7b46ad641147fa8dd8099f2388a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kong@sha256:cfc26cdf8945b232961f8af04351a296da354fc398700d1f9d80f075c3b78b50
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kong@sha256:856517637b6bb8c5f7638c828fd2f1b7726cbb95ea67f6be04b40d571ace1e1e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kong@sha256:279dbefb81d03b1a7308c82d2a73517afd8b85ca4ef533bf9bf6bf88b4b0e00f