dhi.io/vsphere-csi-driver
3-debian-fips, 3-debian13-fips, 3-fips, 3.7-debian-fips, 3.7-debian13-fips, 3.7-fips, 3.7.3-debian-fips, 3.7.3-debian13-fips, 3.7.3-fips
sha256:d043ede3c44f31424a301e4c702ff813840c59eebe0f2be2c97bf2e25af64383
Manifest digest:sha256:7fe4a3ff9eaa628b40a005a0defc1515702cf7e303c85c1e5dd88aa71ca821f7
Size
63.28 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-driver:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-driver:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-driver@sha256:04f0b55777ad842bba92015a0aa9c8cf4aaeb93b0877d4a5fd02685dda5699d0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-driver@sha256:47008eccc39f5f046003b0610df481df01033174277200a1267c6be73ab947ab |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-driver@sha256:b0228ee5e5269dca7624e7a25c01091b34fcc5b0291d3207b47dc8db57d11bfd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-driver@sha256:d7614ceb882e00ac8b5d459acd94fd2a1b939483a3e1f3982df5e6661e7dbbda |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-driver@sha256:4f911d463fb52db1a0d310a8c8af74f89f89e156b77e372b5792c9e40c1f8c6a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-driver@sha256:d0451dd8d985282f5d56dab151316abcbf7dd36c3134db6450817972fcc6a937 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-driver@sha256:efdd38580285733231d52e6d4a4e497e0a608432302a7d47d8b8e6c37719b294 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-driver@sha256:2eb9b1d0cf828d76e9c7491d2340e8437e16be3b7aceff275e4cbff86302250c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-driver@sha256:4ac101d95a069232e343eb6730f38e3b6478d79e01d01b4bbe6e1bd7d0fc8a60 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-driver@sha256:b8c18f50ae96ca576ab778a0001ab7cf542b3ca63bcbc5cbe1fd594d5c52d0f8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-driver@sha256:4aa1b19662f569adaee2867defeabe162a4cd0ad32e66aa40ffc2c42719ba222 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-driver@sha256:49bf4c1b73fa5d03ced7e700ba0750dcdb9fe5ad043e589f2fd82e1fd636018a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-driver@sha256:67d4349b2baa14a8536e897a6dab29f16786fe61edada0c64b672fd04aac3c37 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-driver@sha256:697019e20760071ce4fcb7aa9856a220b1b43a6c7f3b247325c99f9fbacd1e10 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-driver@sha256:615320025ec3a033f8e14711e665ce31d614015c4076c178ec94164408d3f362 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-driver@sha256:99718167aa36382e9726ae9578b42eac13325e4374b44b7610988b8c3dde4c42 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-driver@sha256:19f5c1dca388b131a12c2a3e496b97a87fb31168effcf4aed4a8cff32bc055c2 |