dhi.io/calico-ctl
3-debian-dev, 3-debian13-dev, 3-dev, 3.32-debian-dev, 3.32-debian13-dev, 3.32-dev, 3.32.2-debian-dev, 3.32.2-debian13-dev, 3.32.2-dev
sha256:9770c63cceb15828aadb21dc9eea423829ee9bf3a8217dead48cdbe7e3115c25
Manifest digest:sha256:99bfacd8ec7ec111e68b98f049df9ce72ed9ae76dbd82d4d39ef70ac37ff7622
Size
56.08 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-ctl:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-ctl:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-ctl@sha256:66bffc3035a2e8c8ba4e3757a1c3caef15d95fce5ab9f444db3ebd42c2f2272d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-ctl@sha256:dc5af56b4f592196b27e5b93a686a2d3ee8adea35d70f03aa8d3714a15cc525c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-ctl@sha256:af9f5a32ead546613d773c2d04f6f41fbaf573527d09ec0d566b5b323d6b71bd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-ctl@sha256:833170d8f882e03cf6d256aaa49cbc5421629c4294bdc023ac8c770a187560c7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-ctl@sha256:0a6e811ba20ae2ee99571c0ddb8fb92f6d246f85c98ae32ed34560db9ad9fcba |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-ctl@sha256:24fee214a892c2e74e7835e96bd975696be95ebcf9744f102c323ae18545179f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-ctl@sha256:022ae443ccfa9c416ee2b81defaf78a4ec029243488f27bbe9653089804bc75e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-ctl@sha256:7e6b41766fd982c9817ecb2d70a269c800aa0b72f288f62b303436d044847da0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-ctl@sha256:7d233e3cf691f743b25a7939d2cd27e8022a09da1ffe6d8bfaf451d1b08689b8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-ctl@sha256:d9c56c5f22f3c48565af4f862a38beb7d86535dac213170e8f03b98a503b7498 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-ctl@sha256:e9cac011129c39af638b7ef93102ff6a38a040150c56563f1c831d26c37d32f1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-ctl@sha256:c0ec673f59d956085494264f0a2fa664964d51a39d82ae73da4d9ef07a789cd7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-ctl@sha256:ce4d6b4268290c476eba023d48f323a3477a6bc04aeef8da3c760494681ed44f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-ctl@sha256:be4c60045b1bc5ebe268e3a4013f16c114f23eb8718d1beb0aead350505b7f1f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-ctl@sha256:412b834b33735ac400b6e60f0bda87746bac8892460db35bab439d00f38417c8 |