Sign inSign up
SPIFFE CSI Driver

dhi.io/spiffe-csi-driver

SPIFFE CSI Driver 0.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.2-debian-dev, 0.2-debian13-dev, 0.2-dev, 0.2.13-debian-dev, 0.2.13-debian13-dev, 0.2.13-dev

Index digest:

sha256:651bee4da38029833f8d5f948f4780a476eb4fd3e37e358b7a6c49070bbdd766

Manifest digest:

sha256:1007837d2ebfed3b241c959b94c1638a3fdfbf5c82e2a3f0e5ec31395954207d

Size

31.23 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-csi-driver:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-csi-driver:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-csi-driver@sha256:866b4771e7d17732bdc2f20c3c550626c3d3c4a4859f066f5ad94a23837d7e6d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-csi-driver@sha256:4bbfc8f53c30a41a8ddb84234870c630f274d5a7d3168dc00c620922b0ab3b5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-csi-driver@sha256:bbb342e057f2a92c00377ed407be5518e244719c97708ffbb0b9e060700c5871
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-csi-driver@sha256:09b014d7a233f14e38a09f00ca3abaa4858f84af4bc53a4e62db7f43d9320767
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spiffe-csi-driver@sha256:9ac1e71346bbfbe418fc54eb6be99a227940957ebd02c2943f289ae2e05be7be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-csi-driver@sha256:49ca8a6fa06fa22cf56616621bea2923e1f19d0b6f38c46daef97d523786fcac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-csi-driver@sha256:3a0cea60d7b5ad065dc9d5f873ebca7967f07736f28564c388d012edb017e618
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-csi-driver@sha256:be4f728e153839119b8c55b9a813d8082c757207603be65ea0ee4cb284320184
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-csi-driver@sha256:4fe52ab288f474f6a23a785e191b096907d16233fa5c4a4595f9317896c1cf0e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-csi-driver@sha256:4d9160e02a5de9d51c139130c052b206685b928b4d9986948edfaca8dec577cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-csi-driver@sha256:d300f9998eed852f8b815670fbe681a5f11b1fe9cd17ac5be25ececcdcb7cb85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-csi-driver@sha256:2ea555e9d8f7dec256dbc4dc8a190ba6b9c1fd5cfacb7aec58ef97c61b8506dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-csi-driver@sha256:94f33a166a7deaebc105aed793560e1a59f8177ae05c3e9645808f791324fa1b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-csi-driver@sha256:1122d8ef8d682f871346ae67862517439b0e5e97f1ed0d7da09cbbd4469fe853
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-csi-driver@sha256:695c505b58362dad074dbacde32fa893ec7d2475b2424f70cd5aea5b3cd8519f