Sign inSign up
Tailscale

dhi.io/tailscale

Tailscale 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.104, 1.104-debian, 1.104-debian13, 1.104.1, 1.104.1-debian, 1.104.1-debian13

Index digest:

sha256:d5bd1765764bcbb9b1235dda6b09140cb35916e90f28324472c739838d75d74e

Manifest digest:

sha256:88099c16f13fd3c79c771f7121ab09384e2dd90592b07d75d31a8e994a0aca42

Size

37.30 MB

Last pushed

6 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tailscale:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tailscale:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tailscale@sha256:7b3e598eb4f71a72883733513d93b0f85e969de8a1e97f58e40e01ce411b3766
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tailscale@sha256:4252a9bb7ffdb036d1f26276c427fbe83e23afee9aeab536a7cf0af353760a21
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tailscale@sha256:e8fed450bd3e23f4b1ac707ec54bcd233ba59e120f83e2591fec4ee4848a1442
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tailscale@sha256:b47d7e6e958a0df79315020c01159654f08d5a1ffea7410bec950dafcca8ee44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tailscale@sha256:ca1c9ec4b9ad8bba508c5fa408684a691fce60037774613a39fe08107c664ac9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tailscale@sha256:7a5526d94777eec336d7722f62501a41a5e182be63506fd0ea5b65d7f48c77f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tailscale@sha256:64825323b33af06474eb1e3ec02ec74860e3246b1e6a5e355ced1dec48391715
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tailscale@sha256:81d513f31d993531ea2bab169b6cb048b3fb0f7b67306313ff47f281fbd08828
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tailscale@sha256:5f62371ca1c4d5442ddbee1c1ad7c9b1a4955f2c0b6448390de1d25695cc6bc4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tailscale@sha256:a75c105f3e6ba83cebc0c8c2642dfabd00ac0d31174290404d516bfaa138bb37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tailscale@sha256:23410093eec1a9be46363f7c591abe550db31a0f950d3f4aac5741441ae9f5d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tailscale@sha256:c5551fe1d3ab1e799f393bb7ec88c9a7455b70e589641db4530785089ef6a4d8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tailscale@sha256:720b50186e0f8434af0748fc02244ec8462237a78d97e94c2d4585c8e8b7d5ec
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tailscale@sha256:3e0602a6ae1d543f1bc953aba3d7165ac8b2d1edc572250c5607efed85ef48a9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tailscale@sha256:192fb19785004fac927a8295bc05fd11943bc7c2e9ba226c0969e425b6108adf