Sign inSign up
Calico CSI

dhi.io/calico-csi

Calico CSI 3.31.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.31-debian-fips-dev, 3.31-debian13-fips-dev, 3.31-fips-dev, 3.31.7-debian-fips-dev, 3.31.7-debian13-fips-dev, 3.31.7-fips-dev

Index digest:

sha256:548e5c70c4b963a146f47b7951453e9366b91d80f9af4bedd6268b8650997cff

Manifest digest:

sha256:3fa58d12d99cdd4f1d5197bc4c400fc000ea76f124ab0f95dd0adfea07f21057

Size

31.73 MB

Last pushed

4 days ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-csi:3.31-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-csi:3.31-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-csi@sha256:252ab873e213b8b2e90e1cfc8c945810a6e20499acf2f87217e885af412bb32b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-csi@sha256:fb90d85c78d572a901e42c7068ea426f1518bc585973e6bc859880089dab2028
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-csi@sha256:1fd376ce67c00ceb82496e338a9bd4bd704071cfa9056721368caa01d3b59db6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-csi@sha256:78ebeca8e0cc5c9c2494cbe0eb021eba41de039c2f5d5157c4a57f9fa586948c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-csi@sha256:a2bcc32bdd44fb2413289a5d3b40d66738b09db4cbe6a1d9d16b5cc0951d1836
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-csi@sha256:428feaf087e0f2c2bd335acfdc99a4e74790c6b032b964d755b099af573f1bdf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-csi@sha256:8c7ac6c789608629a0015deffa99dc2680fcf569d204874057b1d91924240d23
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-csi@sha256:d98cb88742bbabbf56e2036eec45c681c3ae9da61630886f12520c33f8db6724
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-csi@sha256:605c0da8cd53b9511ceb9ed9d3416856f5859ceb9e1c6e53f3a2989e29af6801
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-csi@sha256:1ac36eb48ea3bcc1e0336d09d2d30fe8925ada73ceb476dc535d64355c407c9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-csi@sha256:b3b4579a0f6e341fd7cc63bcacc8da4f863ebda3477cad54a4c128a06e16c9e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-csi@sha256:4c7dd1cca503428f3bd1d5110bf5fb61faf1f592bfb88d37628e247fae5e2fc7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-csi@sha256:183dc64b876b1e894546a69a3bd5a803e54c542f0c30346d267d31bb5de0de2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-csi@sha256:54ac5ded8cf38cfa6bfc4fdd7687752cf812267f7bb5ea17b0a686be47d98481
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-csi@sha256:31a9e0c2de3bf3bc2891a03927b9e2754e6296c63b8db2fe1a399b2a37644170
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-csi@sha256:fe9c84df553fc266910e2dc940625cfdcb330b31ed8bed021b2fdd8345a215ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-csi@sha256:dff071c4d5e373c5fed9ff40767167a212ae98003724dd29c0b03a03abecc3aa