dhi.io/calico-node
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.32-debian-fips-dev, 3.32-debian13-fips-dev, 3.32-fips-dev, 3.32.2-debian-fips-dev, 3.32.2-debian13-fips-dev, 3.32.2-fips-dev
sha256:fba15e130c715688a008ab0391cb7db5a678b9ffcb31fdd49ceecb7c43ec9b54
Manifest digest:sha256:d1046c69105c211a66736823171a658bb52e9efe65266c4651ef003e61d719fa
Size
97.52 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-node:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-node:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-node@sha256:a8fc7eb749e0d5afb6fb925567797f54214f68f474b894e77d1875b8f1fdcd79 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-node@sha256:40372f5a8b0c870b14b1deb302f51b65ac3b2cbaf32b1e0e1f5b4cfb18014678 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/calico-node@sha256:96f511b1ea2519d3d41bafec7bb96cce1def58855670c0e99999b45a9baa58d5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-node@sha256:e40c99b97470529abc9fb1de350958185b1e9bd9837c03d79e66896f0749ca13 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/calico-node@sha256:8c1c6c44ebf80f3bd698e7b875fbfb6025e6cdad0662cb87265e416cda88601c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-node@sha256:f6416dd5137c3e95d15a194a07b981fd2977e7202b845f9b24d46649ed82441c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-node@sha256:770c9dbc72a2465cba47fd7a8ef992c83282e5d13bba544c19949067599268cf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-node@sha256:69d6a03cc041c07cd5f069d80de192c7366f1a1399fa93d1a42ea1c89cd341d8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-node@sha256:d8b3b67e0b4a867454e1ab1def95dd3ba223f8927ee047686bd5447928be0cca |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-node@sha256:c00ac2268b4fcd52f0f631e5fed7f1950244dcd2e78c663e08498b41923882ca |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-node@sha256:bdfe5b53aeb2603e5b753416b6f87c94a11505d7a6ee42b9d502a48717895599 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-node@sha256:60cd67acce424a57b505310b6c0eb2bcff0aa8fa4db25ac4c184fed05e40b74e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-node@sha256:005198916858f5d6e5654a49c0d41f4f211c921b94ed48f74baf2fa9fa0f1db5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-node@sha256:b476732db602992633b0bad2e813708c36f1677cc712f8b6c60452db2d3e8e59 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-node@sha256:b10e87a74df9738cd069c02d14d8d1b1f9e7220876c1ec5ab258368550a04609 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-node@sha256:5ad7184a1704fbbd7212d2228790a9e62a44ee4cbfa849d54c9a1ebacd9a451d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-node@sha256:e6d48bac0f2b6f297088a105b78892ba311e5f8717240cb8d8e23f1e44af2c44 |