Sign inSign up
Calico Node

dhi.io/calico-node

Calico Node 3.31.x

CIS
linux/amd64
debian 13
Tags:

3.31, 3.31-debian, 3.31-debian13, 3.31.7, 3.31.7-debian, 3.31.7-debian13, v3.31.7

Index digest:

sha256:2c3fe4ca2eed64f192d1a48e8faa2eaf4784d773a659594078fc7808c5d81b58

Manifest digest:

sha256:943765e9d95cd4f208f2f30aef2542936ebbaaac729bda3e3e06f02ef771dabe

Size

57.41 MB

Last pushed

14 hours ago

Vulnerabilities

0
3
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-node:3.31

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-node:3.31 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-node@sha256:d7cb31c29ca122fc2a351a9440295c42aa8aa2db076dfca35049d23be89c184c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-node@sha256:d002365b70006f80abc0722aefbb60dc2b4c3751909ba0f9e25a123bfed9580f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-node@sha256:dca6a542993db4d49ab20bc2544b466fe8d70b5b76ad2856fc46dd1bcfb4fa63
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-node@sha256:29d3afd96371b8ca93cbd4bbdbbe9700d8add315e15d697f7c1ef413e31caf79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-node@sha256:9b9acf4a8d991d50a570f0ce30db079cfd1fd0bfd7c0b1c27ac06233fcfeae76
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-node@sha256:713b0ad573172c9b7f7f26367083285991f95e10e19c647bf62ff78ba07de2bb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-node@sha256:8975d69372f36db88706d323912b8c7e551e8c433902d99b2984d7c4da3de57d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-node@sha256:47e7ae5f49448d232c26f01d535bb9a6550fa9f1bc7d281947192a774ef7771d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-node@sha256:4dfd4cef4b3f942eaeab8da817b88d08698167257864f0d088be7b41b77a2948
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-node@sha256:dd5c776229172fdc89c13175922c269be2be6377ec220240464a6b4453c673c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-node@sha256:aeafe8efc0df020f8bffde5b7eafb7b5299c9e919f7eb036c41443668909627d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-node@sha256:9e6b3962598e1ef2bb5bcccf70601e6e1d34fca77d37dc121448aec1fabad20f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-node@sha256:6f8a6aa0735f14e8cc9070121ac1c7cf89f1ed2badb3fe3dfc5e7e94f0bb5758
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-node@sha256:19dde56ec3a94c6e032165b24fc060e8876cb7fa622ef658b3c663912079e21b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-node@sha256:128bf6f2dd432f24a919b9c5e01a0d1f8ce08b4b5ef527f54a2ea42d6cc86006