dhi.io/vsphere-csi-syncer
3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips
sha256:63abcf602445aea057e0ff1af39d1d21733b8a0309023fe9ec29ed382a1d1dee
Manifest digest:sha256:7e0708a2842015c1d4705cbd563d8caa12b477726d2c314bd69e6dc4d1858470
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:4010117040000da8dfa0716b6c69bc1dcfc1df218b502adf0746b7ff5a7520c0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:dc6e490adc91f3b9bf416575f4148880a15d9851fe7dee48df0f4d87f35f4906 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-syncer@sha256:113700f88f071f2713f924d7ca9dd2c42796f21caba30dfc91ab6b54810b0412 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:21f210e61aaa1d745517025e91fea291a040c2fb16f30e97be571876c5142fba |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-syncer@sha256:d3644019b8b1846f8318b9a6ef0d12dec3c49834a2b29666e49cf2bcca957209 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:08265e80d0544cdf908245542382642bbf91b5bf83b7fa5074d5505f98384b66 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:d7262e562879060672cb0c0d82bf0a44df256a236c625519b57513831ba49021 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:ab40414dfce86efadeb9ced8bb289ec038c57ae40f08771fdf100f98dd822106 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:7dd1f1d5cdf1634a17baf3d41f67557bf2d25767d7c344f0d58c40dcfca71de6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:f6b42959b7dd80ab90b6bad44b95e7a93dd79a34ce4cdab56ce182d6299cea38 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:237e73d64885d8d54404a7114059048d429de351d65cb6ced3738f01991f3807 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:efbc307136bea11acc413ea9f36a2fc4ec375e8429a2c7f3db40d97b1c0b0644 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:bc864a434a75ef9d09e3b65f12f08b004ef74def1f17adc715987ac4699b45bc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:41f7c2e6bc84a07dbe0d01fb8ede405ffa28c022aa162ac6b67c3acce2e5843a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:c0cc496f13612f316d40ac7e5dacae567c08f4c93dd23d241ee20778523206de |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:8d937ee175ec88e8661f81c20b021dceb13f88d5ea8b51efea8516b040eea71d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:7aa8e73e5563723ba0123dcc8721c7c6be8f61a6ed09b24e9db5d4125e64a7a6 |