dhi.io/vsphere-csi-driver
3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.1-debian-fips-dev, 3.3.1-debian13-fips-dev, 3.3.1-fips-dev
sha256:7b529e64151ccc741459766488e06ff22e98dc89052cabe9491129576a2c5c29
Manifest digest:sha256:4952a8d62a3f091d0e72ac013433ffc590a7d50979b3762c143ea3bc4eb0a8a8
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-driver:3.3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-driver:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-driver@sha256:f45978cd795f9632137c67b1a7c39478fd57c6fd7751ddfe957e8a2d3ceee707 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-driver@sha256:27be4554fac0429079cb4ad624749647564234d6818ddde3212898d84438a727 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-driver@sha256:10c175cd3f504b76a596c5f55268e09bedf04af0686d56b18d018444bc654aac |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-driver@sha256:f60b923afdf1ac8a6a78566c482f66164687f75892a06dd53ecbff0bdf7d5572 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-driver@sha256:cf739204b98ecc27163d3a218754aba209e040c1586003ebec6292f7f77ca3fd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-driver@sha256:8f8a1586f2d2d2824aeec6ee5a74ed55a225b7be6444a435cf49579c4f751a52 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-driver@sha256:a939c76748b7364895b15e8eb23c293b02274a69356eaa696456be4752ca19b8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-driver@sha256:fbac3e2dd15f2966f3548027d9f17f4a22aff7c958124716aec52526e7f4a78a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-driver@sha256:e36df44e53f536c15ee099022719251122eeaa0c074384d012ca5f2b59ba364d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-driver@sha256:b12cba38cdfe419971e4f96769a0a3e954c2e507635d3a71178bf836d28e4ade |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-driver@sha256:a3e63a5194506f6f82592b4d69e3a0fc69c7a34d729a4af528f60b383245b48c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-driver@sha256:e3b7238a720439b30555d020c332337f88f9695529c0d8c07c41b771bdc69d42 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-driver@sha256:0444c09f24df43960575ad2a8efe5d74f3fced43e159e094eab7dea0543815a3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-driver@sha256:8568b8fdb468c3b0fd596f457a33525e4456fb2836ee516192b9c817f51446ee |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-driver@sha256:97c8e97791733c6621642967da2a4c7aa048b0e6006d12f1f5173f2802bf5d62 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-driver@sha256:31c089828aa2a98302cb6009866c76118e35e767e66dadc9d88a8a7d3ba1753a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-driver@sha256:50b4314c8b8781f9ca2e52592cf6fa33c74bf5bbc2812101d1f2db17b9eeea7a |