Sign inSign up
CSI Snapshotter

dhi.io/csi-snapshotter

csi-snapshotter 8.6.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.6-debian-dev, 8.6-debian13-dev, 8.6-dev, 8.6.0-debian-dev, 8.6.0-debian13-dev, 8.6.0-dev

Index digest:

sha256:a6971a8b8a67b76afdd942fe6a4801663915320d542b49cffdea1135e6f082ab

Manifest digest:

sha256:07330bea21c8ccde9ad5d091b987f7d92654b76bdbade32bf76a3f8ebc55e691

Size

56.23 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-snapshotter:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-snapshotter:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-snapshotter@sha256:27b6072a7e8e59bd3022386b674d4bd954eb539453b8b6c11a8d4e9d53fcd726
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-snapshotter@sha256:8afaff774a3ae85b891667b486ff97069b96eaf87fd8f931880eb0fad3b15298
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-snapshotter@sha256:6233cc8737a2212a33a04fc367844926fd7060837e47cd07afc2ac94978126b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-snapshotter@sha256:53c855ec47fff3b7ad0f422a04ed532bd8d8a08844096b3c3d65d29dfa7fdd4c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-snapshotter@sha256:4cce10f35d0574fbbabbe14d7f185d8700ddf926facf947cd48321e0d6459446
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-snapshotter@sha256:68a8982a2c1697774869f8f1555ec9bd2f18e59fefca58164136688558697e18
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-snapshotter@sha256:d03423539a6b340f99aba201e565b136f1c3f4514aba73cafe5167800795a59d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-snapshotter@sha256:49d9aabd7b7aa2de84aea07e5a0863227640b9b1163e17f6084e189db7922492
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-snapshotter@sha256:bc08d8bca028fb701d5147f6eeb39e5c661be21a44afee464ef54a2a8149443a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-snapshotter@sha256:1cbc02b19a016e8b62d216b64c918193898db70e03278d322e65cc925589d2c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-snapshotter@sha256:94a430d1a55a8d4f0b95f96f076f3352cb29ce8266efbd7c167ac1a1a6396c3a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-snapshotter@sha256:5e4e8ad9ab07bf923ca7fb4bad3a77147bc5d81a7a3bbb3139c9018c8c79addc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-snapshotter@sha256:b06a4b6ae26e1c59526f312925a1b8411b562565bf79e9010af1997eab8db75e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-snapshotter@sha256:28bc8f776d0c0ac8e3239059a31befe98738b7535a7c863672a2b37fd384040c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-snapshotter@sha256:f60784b8e61451a6234fab984c7292d45ea2ed9c7da933f200c3a5069916e87b