dhi.io/vsphere-csi-driver
3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.1-debian-fips-dev, 3.3.1-debian13-fips-dev, 3.3.1-fips-dev
sha256:edd24ab5cbda8a5cfde038a8e1ccb6f305836932505cf117c6e30861427af4a4
Manifest digest:sha256:db9abb9736128cccfb07296392048d3ba5ab84cbc2d90d371d65686f311ab38d
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-driver:3.3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-driver:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-driver@sha256:74fd2b1c7777a17153b94a0704dccd55a399682409c14a37c2b28d4d6a6e189d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-driver@sha256:0d637a606f4adedad5ed989702fe64298931adbdd22e967b790d43cbab3b7137 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-driver@sha256:2481efc68540dfcf57d26a307b678cb6f54bb488de46430ce66a5ec6543705ff |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-driver@sha256:8769c56f68c345df5157eb61a467d2ecc3e95a0709626cce5eecfcea54202f7d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-driver@sha256:d995346e3a17ee63be62ef3a045ac402e5976828923ff4599a3ffaca03ba9c1f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-driver@sha256:ba7861fe115167525b31f1b62d9854da627c24c5b20434f0908f97ccedeec6e7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-driver@sha256:716840e9f34042cf78b28ff5f72cc70cc886ee0ac92a8d3a7abcba98a50cbaaf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-driver@sha256:20db8d01ccb5d6e459a1845dcc9c277c7248b5cd0092ad8ad99ac135b59edfd2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-driver@sha256:ec6c1c65637ebfd7a7e514ca9a5229be48ddedb0ed196e5aef37d2e70cd72931 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-driver@sha256:2822c702f2bb98dabd79071fb00809d81224bb8010269f73303e07de28304959 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-driver@sha256:c4b3de59a1a583aa305020ec8b673db12eb0912060f595ce63eab099d43ad37a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-driver@sha256:be7f27df97a260f2f796580a4f6b54a40c7ae37fc72e19fd3880d60667cb45aa |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-driver@sha256:3dc962df8c545313e25f775003c2ce4acded5877776b7d788d4ccc0e85c2488b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-driver@sha256:bb1b1288d52813ea413be9a90a57c064200e811ab51d661846f0eb34e2c15e21 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-driver@sha256:87e58ecbc317f914bca5f866dff1acb832779c04ec9fdb198f65742e0038d549 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-driver@sha256:1f07e42862d86d400f11d56d4677697d4f83639afa26c115a22fb16f7d7bb7b1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-driver@sha256:c76cb3c4ba0a2a766470fe948cfc21cddef4f58432b58303258100c7d6d441fa |