Sign inSign up
Calico CSI

dhi.io/calico-csi

Calico CSI 3.32.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.32-debian-fips, 3.32-debian13-fips, 3.32-fips, 3.32.2-debian-fips, 3.32.2-debian13-fips, 3.32.2-fips, v3.32.2-fips

Index digest:

sha256:73dabb64c0abeab3e018b211935e2f7a14ef1d43e1049d584786a69875a70023

Manifest digest:

sha256:2521f376689e3885dcfe4769d6e962c230705294015b7b2f54cf0f65d0506559

Size

12.82 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-csi:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-csi:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-csi@sha256:da39bd40dce0aecfdaf512d16b442cf06da5472c4eff66a2aa2ca6af2e2938a7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-csi@sha256:65250a3b26734a9784886ddaa339c57a4381ac23c172f068d89e8fb99ddf78cc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-csi@sha256:98afecdfa030dda8a59f9dadce206a6b12765eb3af56445a6d5c94b858aa4549
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-csi@sha256:22cc8a7525fbc0617e4ae67553efe8dfd1f4c7745d131abf421345f669de8eaf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-csi@sha256:0f043966c2bc62e86b9b066b8c20ebf67916ec07a6fe651a433eb512cf574106
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-csi@sha256:393d855d078fa222c5b14762154a12f50ba7d2f9bca4993c2546660e68e7d82f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-csi@sha256:e30f4ec66e5d94adf3f91de35af2446b211fc4e0c1fc8d575e00203bc8c90175
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-csi@sha256:f0c6dfb9eb29694d94caa69f2428592cc308f0f17bc251f07f675dd078b707f4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-csi@sha256:604959f0fd2f7a7b764288e1921edaecdd1d445f5230605a6a61fa1e4c069249
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-csi@sha256:39b652421de0a4ff03558cf5bf6d3b46900c720dfdb48c596c35f27a4eb21897
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-csi@sha256:3b67422bf744520224a6d1c301047aaa7ce364cc75edeacc743552998080f493
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-csi@sha256:d5f35be7a6241898adffaf3585a35862f30945ae4743c7c0581b10b110da3885
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-csi@sha256:66bea8b3dde3abc90127b90e1a0a154237db0aa02fa8b5ab00df94b11f478ed7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-csi@sha256:64d55c769a33b6b292bd82d47c9f6834ac123ca8c3abd05ce9ea503fac8786a0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-csi@sha256:73b38f7f54a9c55493277e5c4f26a87cc5412bbd396014c3b32f6ef8b90f25ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-csi@sha256:683f28dfee34389f0e454cbba922e1dc47f66e87ed911ce7da826eb021e91b3e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-csi@sha256:5fba07c66466c4e2dbe826e1f28aa28a43c815985a8cc9f0e72d82a52a905e67