Package Search Help

You can use boolean logic (e.g. AND/OR/NOT) for complex search queries. For more help and examples, see the search documentation.

Search by package name:
my-package (implicit)
name:my-package (explicit)

Search by package filename:
filename:my-package.ext 

Search by package tag:
tag:latest 

Search by package version:
version:1.0.0  prerelease:true (prereleases)
prerelease:false (no prereleases)

Search by package architecture:
architecture:x86_64 

Search by package distribution:
distribution:el 

Search by package license:
license:MIT 

Search by package format:
format:deb 

Search by package status:
status:in_progress 

Search by package file checksum:
checksum:5afba 

Search by package security status:
severity:critical 

Search by package vulnerabilities:
vulnerabilities:>1 
vulnerabilities:<1000 

Search by # of package downloads:
downloads:>8 
downloads:<100 

Search by package type:
type:binary 
type:source 

Search by package size (bytes):
size:>50000 
size:<10000 

Search by dependency name/version:
dependency:log4j 
dependency:log4j=1.0.0 
dependency:log4j>1.0.0 

Search by uploaded date:
uploaded:>"1 day ago" 
uploaded:<"August 14, 2022 EST" 

Search by entitlement token (identifier):
entitlement:3lKPVJPosCsY 

Search by policy violation:
policy_violated:true
deny_policy_violated:true
license_policy_violated:true
vulnerability_policy_violated:true

Search by repository:
repository:repo-name

Search by last download date:
last_downloaded:<"30 days ago" 
last_downloaded:>"August 14, 2022 EST" 

Search queries for all Debian-specific (and related) package types

Search by component:
deb_component:unstable

Search queries for all Maven-specific (and related) package types

Search by group ID:
maven_group_id:org.apache

Search queries for all Docker-specific (and related) package types

Search by image digest:
docker_image_digest:sha256:7c5..6d4
(full hashref only)

Search by layer digest:
docker_layer_digest:sha256:4c4..ae4
(full hashref only)

Search queries for all Generic-specific package types

Search by file path:
generic_filepath:path/to/file.txt

Search by directory:
generic_directory:path/to

Field type modifiers (depending on the type, you can influence behaviour)

For all queries, you can use:
~foo for negation

For string queries, you can use:
^foo to anchor to start of term
foo$ to anchor to end of term
foo*bar for fuzzy matching

For number/date or version queries, you can use:
>foo for values greater than
>=foo for values greater / equal
<foo for values less than
<=foo for values less / equal

Need a secure and centralised artifact repository to deliver Alpine, Cargo, CocoaPods, Composer, Conan, Conda, CRAN, Dart, Debian, Docker, Generic, Go, Helm, Hex, HuggingFace, LuaRocks, Maven, MCP, npm, NuGet, P2, Python, RedHat, Ruby, Swift, Terraform, Vagrant, VSX, Raw & More packages?

Cloudsmith is the new standard in Package / Artifact Management and Software Distribution.

With support for all major package formats, you can trust us to manage your software supply chain.

Start My Free Trial
 Public tetrate tetrate (Tetrate) / getistio-containers
Tetrate Istio Distro project (formerly GetIstio) container images registry

Docker logo ztunnel  ad8b0319d33f0322133f69cbfcf…

One-liner (summary)

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

Description

A certifiably-awesome package curated by Bender Rodriguez, hosted by Cloudsmith.

License

Unknown

Size

13.4 MB

Downloads

0

Tags

image arm64 linux

Status  Completed
Checksum (MD5) f04c69e8c082ce8eece53c31b208c61c
Checksum (SHA-1) 9afc7d0a2b3645a71c37cad226087ca343d9ab54
Checksum (SHA-256) ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8
Checksum (SHA-512) 7c6fd5b579288ee37cb3b0352e5b57404cc692bcc43e47aa0b3a2c9ad4a451b35a…
GPG Signature
GPG Fingerprint 7490c226a7c21a19bb1d09e800b3a57eef287d7b
Storage Region  Dublin, Ireland
Type  Binary (contains binaries and binary artifacts)
Uploaded At 3 weeks, 3 days ago
Uploaded By tetrate-ci
Slug Id ztunnel-b6fq
Unique Id Wkaw3Gj6hpqF
Version (Raw) ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8
Version (Parsed)
  • Type: Unknown
  docker-specific metadata
Image Digest sha256:ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8
Config Digest sha256:dd9d500eb1a0fb89c1d59f453c8debf8ce86034019552219cc53249f3a89cd57
V1 OCI Index Digest sha256:7ab08ca4fd2d371f457757d05515116020ec65e4ac0e9e27da9869d40529d927
V1 Distribution (Signed) Digest sha256:d5191f83fba65bf0edbe9865ae936c3292da16e908a7155bc117b656b541995f
V1 OCI Digest sha256:3382b56673ad5a79d011a542cbe41e38b100e58127ed7347a3e189f8efc4c14b
V2 Distribution List Digest sha256:69afd3cdd0e5a388d9d1d6f95a5b6b485d5cddef25138c4295cb9c2f989c97c1
V1 Distribution Digest sha256:27f711c1c7ff220a62db9abdf363b03bc5174b3cfc33865fdb419d7b29b006d3
V2 Distribution Digest sha256:ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8
  extended metadata
Manifest Type V2 Distribution
Architecture arm64
Author github.com/chainguard-dev/apko
Config
Created 2026-06-26 00:44:13 UTC
Os linux

This package was uploaded with the following V2 Distribution manifest:

{"schemaVersion":2,"mediaType":"application/vnd.docker.distribution.manifest.v2+json","config":{"mediaType":"application/vnd.docker.container.image.v1+json","size":1931,"digest":"sha256:f72d761368e8d149067dd5c03d06695654ec1f789ef7b2335336e9aac8b4e3a5"},"layers":[{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":7201862,"digest":"sha256:6edd4204c61a2b7c2d7c26e8d98080a29f962ada0f95a0da6f75c04078b2920d"},{"mediaType":"application/vnd.docker.image.rootfs.diff.tar.gzip","size":6860639,"digest":"sha256:145921dae4d0749324e44b8a0d423b1749d2217cdf7348c03bb7ce472985d7c2"}]}
Digest: sha256:6edd4204c61a2b7c2d7c26e8d98080a29f962ada0f95a0da6f75c04078b2920d
Command: apko
6.9 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: WORKDIR /
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG istio_version
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ARG TARGETARCH
32 bytes
Digest: sha256:145921dae4d0749324e44b8a0d423b1749d2217cdf7348c03bb7ce472985d7c2
Command: COPY arm64/ztunnel /usr/local/bin/ztunnel # buildkit
6.5 MB
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENV ISTIO_META_ISTIO_VERSION=1.29.5-tetrate0
32 bytes
Digest: sha256:a3ed95caeb02ffe68cdd9fd84406680ae93d633cb16422d00e8a7c22955b46d4
Command: ENTRYPOINT ["/usr/local/bin/ztunnel"]
32 bytes
Docker logo
ztunnel
image amd64 linux
0 tetrate-ci
Docker logo
ztunnel
image arm64 linux
33 tetrate-ci
Docker logo
ztunnel
image arm64 linux
0 tetrate-ci
Docker logo
ztunnel
image arm64 linux
0 tetrate-ci
Docker logo
ztunnel
image arm64 linux
0 tetrate-ci
Docker logo
ztunnel
image amd64 linux
0 tetrate-ci
Docker logo
ztunnel
image arm64 linux
0 tetrate-ci
Docker logo
ztunnel
image amd64 linux
0 tetrate-ci
Docker logo
ztunnel
image arm64 linux
1 tetrate-ci
Docker logo
ztunnel
image amd64 linux
39 tetrate-ci
Docker logo
ztunnel
image arm64 linux
0 tetrate-ci
Docker logo
ztunnel
new image arm64 linux
14.4 MB 12 hours ago
0 tetrate-ci
Docker logo
ztunnel
new image amd64 linux
88.1 MB 12 hours ago
0 tetrate-ci
Docker logo
ztunnel
new image arm64 linux
88.1 MB 12 hours ago
0 tetrate-ci
Docker logo
ztunnel
new image arm64 linux
13.2 MB 17 hours ago
0 tetrate-ci
Docker logo
ztunnel
new image amd64 linux
14.4 MB 17 hours ago
0 tetrate-ci
Docker logo
ztunnel
new image amd64 linux
88.2 MB 17 hours ago
1 tetrate-ci
Docker logo
ztunnel
new image amd64 linux
14.4 MB 19 hours ago
0 tetrate-ci
Docker logo
ztunnel
new image amd64 linux
88.2 MB 19 hours ago
1 tetrate-ci
Docker logo
ztunnel
new image arm64 linux
10.1 MB 20 hours ago
0 tetrate-ci

Last scanned

3 weeks, 3 days ago

Scan result

Vulnerable

Vulnerability count

2

Max. severity

Medium
Target: Wkaw3Gj6hpqF.sbom-cyclonedx.json (wolfi 20230201)
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc
Installed Version: 2.43-r6
Fixed Version: 2.43-r7

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc
Installed Version: 2.43-r6
Fixed Version: 2.43-r7

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: glibc-locale-posix
Installed Version: 2.43-r6
Fixed Version: 2.43-r7

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: glibc-locale-posix
Installed Version: 2.43-r6
Fixed Version: 2.43-r7

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Package Name: ld-linux
Installed Version: 2.43-r6
Fixed Version: 2.43-r7

References: access.redhat.com inbox.sourceware.org nvd.nist.gov nvd.nist.gov sourceware.org www.cve.org
MEDIUM

CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Package Name: ld-linux
Installed Version: 2.43-r6
Fixed Version: 2.43-r7

References: access.redhat.com nvd.nist.gov sourceware.org www.cve.org

These instructions assume you have setup the repository first (or read it).

To pull ztunnel @ reference/tag sha256:ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8:

docker pull containers.istio.tetratelabs.com/ztunnel@sha256:ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8

You can also pull the latest version of this image (if it exists):

docker pull containers.istio.tetratelabs.com/ztunnel:latest

To refer to this image after pulling in a Dockerfile, specify the following:

FROM containers.istio.tetratelabs.com/ztunnel@sha256:ad8b0319d33f0322133f69cbfcf8c3e893e3b1713254056885ac07744726e2f8
Top