Sign inSign up
Calico Node

dhi.io/calico-node

Calico Node 3.31.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.31-debian-dev, 3.31-debian13-dev, 3.31-dev, 3.31.7-debian-dev, 3.31.7-debian13-dev, 3.31.7-dev

Index digest:

sha256:0a2a6f684fd632b612b2fe1e7871242ee8f73669dde0c48db643450b94f1fd2a

Manifest digest:

sha256:c5b282fcffe75140afcc5bedc54eaa5c5bdbc860f236d4be8042f3ccf8afe800

Size

94.32 MB

Last pushed

11 hours ago

Vulnerabilities

0
4
5
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-node:3.31-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-node:3.31-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-node@sha256:60c05c8e20198835868049af72ad79054b10c16b0afc923da64e8b9d38473e63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-node@sha256:10ad7f9f0cd678d874895d50f5aae9e472921c573f153ef76dcd305110b813f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-node@sha256:ec95ee5fa67a113da208cd07fc113f4ce2f8d4c135bcd3a57dd4b5465aad9b57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-node@sha256:26ca182e5375813168400b0532bb184a0b04bc8404ed6679b3b293f11029afef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-node@sha256:627e84475e51d94821536196b2bbe2fab513fd6b425ba58634bdae18ba1b3c8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-node@sha256:afde0b4a69cbe16a9700bcd1e9df0435201388660dcc4a795af21f7ccfe73a05
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-node@sha256:9e7902e9fa1d17526f70efe20a46157d0cb9fff6d9f8224297cd51f0c20e6df3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-node@sha256:b492e533f8b1add715d4f6a70485855405b9cc0e2a00f11209b1d027e1b9545f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-node@sha256:f5f3f605a8ae0f666035350e384a3e28c31888cdcb564090fa5c030cff6c9e77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-node@sha256:439b46062fada1cc96a54f4f64c37334080f4e956932fad9004aa3307879265d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-node@sha256:686dad4ca76c90875887feef6f7a72dc42b460472118736acbd03b8b40315993
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-node@sha256:650fe8a58e6d12ec56132cea419ddfd64a2cfb06877809d7000343bf49d11b01
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-node@sha256:2050d6c8df52f0b853aa7b96aa12d9252ff1bfdbf09ab98b0d0abc663f59ad71
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-node@sha256:c23440bf45ed924403d4de12df804a48547f7f763ae82b111d46755971f98b8b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-node@sha256:58958c22b0a465430c4b3dc4b7a90883568ad064e021891388c8a18c8af347df