Sign inSign up
Tailscale

dhi.io/tailscale

Tailscale 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.104, 1.104-debian, 1.104-debian13, 1.104.1, 1.104.1-debian, 1.104.1-debian13

Index digest:

sha256:3ea67112f858c2e4d1afbcf910134675160c83d80bc03731f727ad98308426db

Manifest digest:

sha256:b1a2c585edb237b6c6a7e10010b91028d4a1bff6806cf4184eeeaf9a8ee98ad1

Size

37.26 MB

Last pushed

2 hours ago

Vulnerabilities

2
9
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tailscale:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tailscale:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tailscale@sha256:d51d3e5a3b4225625882ba205019f07de732f29cc78ffcb12e7f1fa59062b870
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tailscale@sha256:c6087f07b790019cbbe70908670945aa51407b49a4293f3cfd225e9913c05dd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tailscale@sha256:ceb1e17844e0e7005de12875cff42cf491a5f7309aa5b49ec9fb1e558bf383d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tailscale@sha256:5c409f923d6127bb8f472b11b042bd2fe83a369ff484d06cb08bac7108c0baf8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tailscale@sha256:5cbe9a4a9402ca155b81f36a8a890370708d08a1a438013146171c8c06c19475
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tailscale@sha256:77424298456c687686652e8a508cd47fdce20aeb0ad32bdea7cdaafddf2e9db8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tailscale@sha256:f664a131caccae5752d98916fa0a17d6b5d4129149b8f7df60d29bef37e27819
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tailscale@sha256:1dadecca92496519df11d164adeec1ecce7f21e8a8ddb33bf542aed6bfec8ff0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tailscale@sha256:736e48d02817024c970f1ade719e9d3c1622b84aeb4521486045a706e85e5f27
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tailscale@sha256:52851bf8baeb1d6a5a8b5bb08a57e23daa1567f3cba2a624e8460c9815b1fcdd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tailscale@sha256:b4d5ee0f6f67dae8b15d35c12760380ad06fdaac19df1e8db06ccd034372b929
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tailscale@sha256:0c1d7e622cf8bfc48fb8c01cf0b8f3ef8f451f23b25e0144c7fd27218c154500
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tailscale@sha256:c926bf259b22070907d9b964c347d8917be34ea11931b5807801c7dd11a7a9a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tailscale@sha256:dbc6d27bdaf342549dbf28ad7b295c879712b1282d69dcaaec2807440ce0937c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tailscale@sha256:0dd40f28d3231304e5e69cb4af8a5a51159b831ffb19bb4b865e0949248fc8d4