dhi.io/vsphere-csi-syncer
3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.1-debian-fips-dev, 3.3.1-debian13-fips-dev, 3.3.1-fips-dev
sha256:978dde572fc7650e3ba63765b27863f6115d010ecfd65216f5ce0c64c2cb9459
Manifest digest:sha256:c93293f71420525b39f7f7e3e287cce4ba7bbc02c669d70e77825102ee671f5b
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:90bf2c55047de9bf3e8914aed5f379795eb538ea77d4ac8f692ceae1afecf42a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:b60528c61167f47b4a2776540eef0b15e13e90677309ef6b97dff065f5cfc116 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-syncer@sha256:2dcb7a01df80fe79da0965d6e213b2f6c45be29064c8da74ca515c900ffcfee5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:a834486e21f1887bc70f55b4842e09c8dc6fafd16a8ae5a9e9fc95f8a2749adb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-syncer@sha256:5f9a7bd13f839f4386c2279928cca4cd3fde0cf107264571a1f0328ecfc1287f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:b4a09cc8bcca0df79198b118a4663d26744aa7bfb38d273de0b9df8ac9bd3d14 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:f277fc30dd82698a588270aa26d6ce776ff41e3de90e7544da6acfde8610420c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:b568f1c9f31c9845d5e3d3f443d768c9982fde74dc51af02bdca4cfb203857fd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:35d768e4279c9876f2de260136990a9a3d8c70bc356842c39c501ddee31dfd3b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:87a49c17cc317a3067f955ffc0751cb15f69a6e0558884006d682b20b4e2db86 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:2124069575c04dbf0d100c61812eb8cd69f149b8ef9b8164e755968fe58e1f9c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:76a19adc2305be21d1fa82f9acfeb5ed66c3973b569cc9ca4d546ad7deae3226 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:d5b0c69174a6bb0a84c06587f090065da22ecb4da9c3a3126575b36218017a80 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:3a056cc33fbb481eabdab8ee7377cfe447de328091dbbf288fbbe94ef328ec4f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:bd4a22c5d24db1f9a5baaa0b92e095587331b066475590e1b73f6f91f96ce29f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:87983cb06e2a40ce9a1f995ab2257a6e0dc622fcbec8b13dae13c3457be527c7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:3681fa776940f5618304e4b6ef2e143bf6c030fce5e2317cb6d2731cf783e97c |