dhi.io/vsphere-csi-driver
3-debian-fips, 3-debian13-fips, 3-fips, 3.7-debian-fips, 3.7-debian13-fips, 3.7-fips, 3.7.3-debian-fips, 3.7.3-debian13-fips, 3.7.3-fips
sha256:7843ff6eac5e269619d353166fd229ed5e33d95ab37045fcaa5c4fb15a422678
Manifest digest:sha256:92d66abfd9b53ae4cc0779b6241dd9614ad7c72a32ba25f65cfaf9aa183cece4
Size
63.26 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-driver:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-driver:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-driver@sha256:e0fc4a6678aaf3ec0c2666407c33c61b3be416c53ecb617f5b480e7de4ce1c77 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-driver@sha256:214294a49f66061ab6ae4b889c3c7bf7cd391bb10771c9b40c418c1ff0771971 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-driver@sha256:aa7c8021b75eb1d56b151699174829530e950349cd2d2eb2b72f8b46d32e5835 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-driver@sha256:84ba678a475e4ff8f5ecf6ba0981c6b4130b822dd46f64051f71e8ed5964224a |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-driver@sha256:5f9b7aa3141e3e815b32b7bc32354674100fd5f9497ec8cd0efd00c0f12a5513 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-driver@sha256:cb79fe2ddbd9c792ad1e374d828d39abe9a1d602359ea504e64544231309f066 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-driver@sha256:5d841c2b7c7bf8e4ede412945624de9d6f465a781c1088caa8a98d6fcc139243 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-driver@sha256:d8ca1241f363d3f3738a1ee9266bb44bf480ec3d0517c923fbca90192a16325e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-driver@sha256:f246855b559f4aac482b3f2423a8d55b0cae051d04ae2c7c58c6e35c61179eb7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-driver@sha256:405c6776b6085b60cbc0641c2fbbc3963e58635b2a62ea7a0d23c5c5ea693875 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-driver@sha256:cb2b6d00a39cb04360aee83037d7179629632582162c4d411cdbf29f215a547e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-driver@sha256:e1adac371a0e326f636e516792c7b838b422effd4359532f05a199b6492f01c1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-driver@sha256:1904bee5c62a9b759862dbac764013f63994ff06fd0a90cfc2513011cae12f12 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-driver@sha256:eea8dafe96091e70583c1f980b2e665b4a079a7a5051bba7f569a81e45e7da57 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-driver@sha256:bd7d51ae8aa569ba52e2bcc293d765470a2fe4ff15f771cd60fbcc86546ec304 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-driver@sha256:3218288f1298e85c31daaf59f6441fb96260c52702c3cf835497280c8b355664 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-driver@sha256:6ff19f08a09112e6ca8d53b7e4d3fc41abb7788db475f5d3075225df4492dfeb |