dhi.io/calico-apiserver
3-debian-fips, 3-debian13-fips, 3-fips, 3.32-debian-fips, 3.32-debian13-fips, 3.32-fips, 3.32.2-debian-fips, 3.32.2-debian13-fips, 3.32.2-fips, v3.32.2-fips
sha256:e0a57bf0edf2c0101907293a17f6b520ef01398de75fc92ef92d1a9244a1bf28
Manifest digest:sha256:28ec2bc014c3b9c6129ba2802d8d2002bdd0306edc8748716b407c19f99aa45c
Size
29.77 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-apiserver:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-apiserver:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-apiserver@sha256:122d3f40fb6b3e2ef2f52291b744b0d9226a148300fea4d4a0814506567fdf44 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-apiserver@sha256:94bd75be1f3ed63fb962fd30b0d97276d405ac49b891925fd06e4c5a9ee071db |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/calico-apiserver@sha256:b7b6ac4657a3c3730333c90d49c26bc35e6bcfd53a4d4757d74adf2642cecd9c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-apiserver@sha256:24e3348c9721407be0aa30df4d95807f84fd57c028461725b578fbbe2e1f6312 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/calico-apiserver@sha256:b6c7fea4f5a13cdc821f6bbf44858d0c343b236924a4e78481ab889acfe1a52d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-apiserver@sha256:2b89ae1ab79ab918e8d78575a3b18ee790f45437ad45a96c54e166ede7d1d21d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-apiserver@sha256:27b3b635eac36a38e73292c0dc6281491f2373d1a767412abaea9cd41bd51766 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-apiserver@sha256:323a3100cfec7d1a50d130259ad28ad111b7ed27557ccbf1ad35881ac7735c26 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-apiserver@sha256:a5eddbbb4492c0d77cea3df3d80cd05f8ba505752c619aff6bf4713c2dfa81c0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-apiserver@sha256:15086dce22d9a9b7748879eb766d0e7b4fa8ab6bbca71a713f6c449f5509c96b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-apiserver@sha256:b195c750d5e46518bb9403f111e1b12a13f5bd4ecec30a34ceeb75ee9ae74611 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-apiserver@sha256:07013666652798ac56bb6c3c9e1c1c6bc138de109bc03891e6e49ec480eff1b3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-apiserver@sha256:c7bf4dd8b5edf4bf6b5283b2505970aa8cd9b7998034d0fd455da6df80668b30 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-apiserver@sha256:d6cdc9158c5f5636892788098de62b7d18a0d6e0b606ed6b73033ad6f46c1eb5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-apiserver@sha256:9a188142c73315ca259f587d8b93167256cd29f04aa0902bdff757977e61756f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-apiserver@sha256:58703f3359e9728cf4e9b85597fc1fc3aa80900d299a2bd332ae5941dbb06680 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-apiserver@sha256:d554196a62d95bbf3a523a1fcd9610da98b784257ff64b8d5e1ca1aee01bfda6 |