dhi.io/vsphere-csi-syncer
3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.1-debian-dev, 3.3.1-debian13-dev, 3.3.1-dev
sha256:198e737271c195fd31bb9584fc56bcfc22614b31fd58a4b16a0eba27bc75c52f
Manifest digest:sha256:6973a5f652e622eeb8ab80d11d4999fc7fff14b1870a36dead7c36505f8f7d78
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:a2926242b33d328736ff1ab8d230a0647ec40d7d2bcc316111b87d7ac5d235d4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:bf25559e0f969fc4184d2bd511777493e5b2b0cc120e33b1676151f605d474d0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:c6d99aa5b9a07c33254881643e509e65ca08d6308d378267e75a0af92e82d296 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:f7cdc240fdc889fd8ddeafea89db80fe2f259f30c7194ccd862575dda0b38b26 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:de9d670163d09156a4bde513152c162a3ec360cb729e3637a7a6cfb9618c537a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:f0e8a9ecc9434922e3b1d5aa4ab124054262bd0dc44734be89bac8abcd279874 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:50cfcdcba66d0fc8a573829f8d991005f49289aef76cacdfa7fb8ffee0b2f5f7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:50d67b82d0d68a6024dcdd47994e9b672df36b79aaf805280dd335f8e3298cd1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:b5fad720b9dbc20a9a705446344605fc8b8d027d1274b46a5668d85b1d8b5fcf |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:99cccf6a76063056550399f40411418060abf35f7aaa5f33341d7dfeea5433e5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:1f135327f78c51d7537328d027e4758d018b029bb881028c264dc0c46962a6f9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:2de9b61c7150db7326336b6a48e27c5f91d68e18cfefa9a006f136e15c25221b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:39321b0094eafff25c376094566ca85acc4d63bf512fbb6d7b2b9b8b7ef4632c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:d24f6858e02eee97f6476c6dc7dc749b8834205dcd55e99ab27b9831898b3caf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:9806f7f4ffad97de5635bfda609eb31e69e73c8389aef1d9ed31185b480c2c42 |