dhi.io/calico-csi
3.31-debian-fips-dev, 3.31-debian13-fips-dev, 3.31-fips-dev, 3.31.7-debian-fips-dev, 3.31.7-debian13-fips-dev, 3.31.7-fips-dev
sha256:548e5c70c4b963a146f47b7951453e9366b91d80f9af4bedd6268b8650997cff
Manifest digest:sha256:3fa58d12d99cdd4f1d5197bc4c400fc000ea76f124ab0f95dd0adfea07f21057
Size
31.73 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-csi:3.31-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-csi:3.31-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-csi@sha256:252ab873e213b8b2e90e1cfc8c945810a6e20499acf2f87217e885af412bb32b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-csi@sha256:fb90d85c78d572a901e42c7068ea426f1518bc585973e6bc859880089dab2028 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/calico-csi@sha256:1fd376ce67c00ceb82496e338a9bd4bd704071cfa9056721368caa01d3b59db6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-csi@sha256:78ebeca8e0cc5c9c2494cbe0eb021eba41de039c2f5d5157c4a57f9fa586948c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/calico-csi@sha256:a2bcc32bdd44fb2413289a5d3b40d66738b09db4cbe6a1d9d16b5cc0951d1836 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-csi@sha256:428feaf087e0f2c2bd335acfdc99a4e74790c6b032b964d755b099af573f1bdf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-csi@sha256:8c7ac6c789608629a0015deffa99dc2680fcf569d204874057b1d91924240d23 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-csi@sha256:d98cb88742bbabbf56e2036eec45c681c3ae9da61630886f12520c33f8db6724 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-csi@sha256:605c0da8cd53b9511ceb9ed9d3416856f5859ceb9e1c6e53f3a2989e29af6801 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-csi@sha256:1ac36eb48ea3bcc1e0336d09d2d30fe8925ada73ceb476dc535d64355c407c9c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-csi@sha256:b3b4579a0f6e341fd7cc63bcacc8da4f863ebda3477cad54a4c128a06e16c9e4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-csi@sha256:4c7dd1cca503428f3bd1d5110bf5fb61faf1f592bfb88d37628e247fae5e2fc7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-csi@sha256:183dc64b876b1e894546a69a3bd5a803e54c542f0c30346d267d31bb5de0de2c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-csi@sha256:54ac5ded8cf38cfa6bfc4fdd7687752cf812267f7bb5ea17b0a686be47d98481 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-csi@sha256:31a9e0c2de3bf3bc2891a03927b9e2754e6296c63b8db2fe1a399b2a37644170 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-csi@sha256:fe9c84df553fc266910e2dc940625cfdcb330b31ed8bed021b2fdd8345a215ba |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-csi@sha256:dff071c4d5e373c5fed9ff40767167a212ae98003724dd29c0b03a03abecc3aa |