dhi.io/vsphere-csi-syncer
3-debian-dev, 3-debian13-dev, 3-dev, 3.7-debian-dev, 3.7-debian13-dev, 3.7-dev, 3.7.3-debian-dev, 3.7.3-debian13-dev, 3.7.3-dev
sha256:0dcd181d8b40353ea81007d9d88852418c4da5ecb43c0a6762661cf9d1f33f32
Manifest digest:sha256:f4c4d5d432ef84d23d0300017a8fae7fbd16150f2e780132f443f4aa7bf95ae7
Size
60.97 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:961e53063ebffac0be69bbbf06bc01aae313c04aefc35f7ca2b87cf52b2af5fd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:3fb88145a9adf521edbe17b3998f2d563675d36448c08277fa6a48102c1fe953 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:9d74c7717f210d51ace09917763242de857d247ef46c7c6cd28507230d3dec18 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:9ce01730d2cc0546268821a6408546d21ea17f16103c38289fd8a6c442994527 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:6fd3814d711125c04220cefcece22b8abd16762e4a748aa9cc4d2ba566370416 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:a1ebffa7916f3436bf3c3d7c9a934c1c5dd3ebca9e851f087ee1018239281058 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:8cd95eba87da27fb27258a3e8ab4654ac840d0388b491eb530a95096144df7c2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:f27590ef0d1070fb84911a2151645ad280534b569fb34d0720c7ec5f2120d973 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:6fa4c0041d68b2f2877047305e3246885028a407a8e9786eb8e0796e694ba0e4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:55062adf9dfc31cfada88252a6ef829635f9fa3589de92ec7eeea130c8772092 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:36c12f57e71ba2161fc8537365ea082f4ba8f97c12046b0ee29fb3da832ebdcc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:c8e5bd9509d355bf81679d7a490db2f4d59541f039342ab654ea2f2b4e478e81 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:0a049d7a9a7c69c892e97f6aae099126213eb4c375098d3ade71e7832e1fe386 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:db29a579ae18690ea1fd5a74f5edb02aa0a61026b3367461ac79ce758a7bf5be |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:535cc9d60f709ec4dea5b348b03ffb8cf980929673ee50e3adcb3a8baef64ac8 |