dhi.io/calico-csi
3-debian-dev, 3-debian13-dev, 3-dev, 3.32-debian-dev, 3.32-debian13-dev, 3.32-dev, 3.32.2-debian-dev, 3.32.2-debian13-dev, 3.32.2-dev
sha256:0c7a928a5849d80d7b2cac5a983e9e8d81b428d5487ac5c9f211ce13f0c0be27
Manifest digest:sha256:c5a39de8408eef0bb4e8e1db8aef0ffdb3dc185c41d526a6ce69af06130b9a5f
Size
30.99 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-csi:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-csi:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-csi@sha256:03606866c86f593359e7099ebdae00fada9051fcb807b2a075200c9c3e08d06a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-csi@sha256:8c4bc1a85c00566e15838bb98cb0c90533df6d3e7992da4668a296f7ccee0194 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-csi@sha256:74c92b4023450b466f471603e83ec10922e92c7a95f94291641d5b34eb3bc228 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-csi@sha256:7b846ce7626995986e455693698b5335d9187f391d84bc0f06ba455663d67bb0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-csi@sha256:65cd42d4e912b30116d45db677e012789835d2ef61e2a20d86e782cace4bb2ad |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-csi@sha256:99c6c96942c84d860bd2e12d42cc1c1d554bc5ab800a3c882639852bc8170541 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-csi@sha256:05da0e7a770651feb182d5f3dfd917a631f3b2ecf77446df2edf1c41a0b4cff9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-csi@sha256:fbec41da68fe963ab8039677f28bb671723d73c620d0af5b6617ea227d57ccda |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-csi@sha256:b99098a4a5dde7749129059f0316f4645dfcdbca9479b6fecb78e6c72302bd28 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-csi@sha256:4b33057627cea3b5d88d7808c33f39902b4e1c05f321364d58a31a70e182e9dc |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-csi@sha256:18eb4412edc9f6ac6438cff03ba1d31196d9102362bd6060c31c40ac3bc733d9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-csi@sha256:d441561c40ba9d7ead47c6dde3cc1c535dffd9f9a2841bfa10958427a76eece6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-csi@sha256:d85bfa636b73c53cb0b5311e86b2cae849bbb5e67c57762922431b1530ed1da9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-csi@sha256:79b28dadc57532885e23eeb15b905831100806b0cb235b418a487a8d40ebb09d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-csi@sha256:a5457168d2ee1f4c03c8c78ac7d132bfc447b510a72ae5fb8f0f274241d9de3e |