dhi.io/calico-csi
3.31-debian-fips, 3.31-debian13-fips, 3.31-fips, 3.31.7-debian-fips, 3.31.7-debian13-fips, 3.31.7-fips, v3.31.7-fips
sha256:94052edfbdfdfd4ad50361da2ee1c0e5bbe0ab81a50c31a084e05d6fe7b77232
Manifest digest:sha256:52b30c7dfe6d904877ace0ac2673daf9bba85b46978080922fdbf233641c7365
Size
12.81 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-csi:3.31-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-csi:3.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-csi@sha256:d90510ac2eb19f970c1b6915a45e9eb0145e1968493807a5ba707c4bcf82d4ac |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-csi@sha256:db6844ac8f3387ff04765e5acf0598da40839f061aada5abaea7e06d954f1e2f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/calico-csi@sha256:5e84ed6c4c2e1a4d1656f5b20b85058ab33e5c0a26ac103609423831a0a8fb62 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-csi@sha256:215975f08bc45b9d5647a1044d374ce05b8f56212d101e859d0a5c91ae7304d5 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/calico-csi@sha256:d3eeb673da629b3ddb2b8554eda20b52ef9d2e3110a451ce2232a6b636830f90 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-csi@sha256:a0344e7a98ae315f33ef72427e3557d7983e24cd5891cf4a3181b9d36adde4d3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-csi@sha256:adcce1a1bcef8a8cb79f598b8aec74fab5db87e3afcd49d176c1ba52921ad573 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-csi@sha256:4c1b10193bd31618bb14a1bce497860699ded8ee689a94c3cc0ae54288ecfa01 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-csi@sha256:051aa8a554b22a1b4d75c891d9e4a694d26dd51820d7012cc78232d7965c0faa |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-csi@sha256:73c36db6b7ce51fbed4210f6a6b7f252667530e56b935457ddbdaac58a56044a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-csi@sha256:ecad35745d83a344f7545dafb31ee56881a69ab386a25b888c5f6a66875d46c9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-csi@sha256:c6ebcbfa657ab039588f836061e86726d63d81b268a79116b1f1d9cb0492b1af |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-csi@sha256:9c7853d2dfeaca91e45b8c3b29e622330c2652b870e2562bcc400faff64c1d51 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-csi@sha256:7f5d3f78b8b21fb71abe5954d39e64f0b9d8476e78335f84b6685fd0b00ecccd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-csi@sha256:ef6c264fb9fe8f8203662c5a5838b291e3b5123a2ed1bfc8225edda814325e65 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-csi@sha256:03156cb3c5519ac1d5f07c45f27e2091c9db41c09e1c936b0f5f27a4a97e258b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-csi@sha256:7ab35bd30aa2a41bf0ad033caefa6d5b94a83392c2349a1715d28079b70c9a64 |