dhi.io/calico-goldmane
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.32-debian-fips-dev, 3.32-debian13-fips-dev, 3.32-fips-dev, 3.32.2-debian-fips-dev, 3.32.2-debian13-fips-dev, 3.32.2-fips-dev
sha256:22d872cbfff0c1a813436434a42afe4728536a9af14f575ed1584f7f2ac6f6e9
Manifest digest:sha256:a1379f0b9b64da06319e3ae709a9e90d7a31c1b4091a2b3fe0aedef81a215a82
Size
70.70 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-goldmane:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-goldmane:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-goldmane@sha256:ba9c9cbf0c20d4df7b0792fc4e31c9a798c8ebcb8ceb0f91edfe23a0f0b50c12 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-goldmane@sha256:b13c8ed2c5140bff3fc503b99a945a47929c62b2a7125c362b5efcd0c13fe08b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/calico-goldmane@sha256:942198b8761371f7dbc7e4030b9822fec77f83950ca1149dc9c519b0503473ee |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-goldmane@sha256:d3f162e35dc4f97da620c559d8294cfcd26fa2e07e9ff6d5e6f65dfa070b5bab |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/calico-goldmane@sha256:b30bbc1a7abb3f39150687111de9fabc198956214a03425910c6caf2c84876f1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-goldmane@sha256:aac5982be49cea3b1fac344eede9b68569d36859d98792ebbe48a368aadbc2d4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-goldmane@sha256:8c28d7df5437c8152c43328fdccf6d8c8d45f419afbb3a580d7279cf883b2a9a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-goldmane@sha256:dcdd4dfe77cbb526a8189daac5a0bd3a2870bb6da2cd2d7f77263740d1bc7876 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-goldmane@sha256:02d14f95457fe796d4cc8ba2e15d57d1cc069befa225dd926ff6e746e7fa72a2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-goldmane@sha256:c081710b98006257d306497c8db7c2ee8fc04215d0ce8a9362f7f3ae67bb8b6c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-goldmane@sha256:03f35cfdc4f19e56d1194affc186af92758b3fa2521ff27954dab493fcab03d3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-goldmane@sha256:15d1c7c1d34be2e614f51943e1a2a552f76df83c8cc3e9b02289bdbcba544424 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-goldmane@sha256:df5371a8ebc2938c0717f1a32da792486d343e260d8a5912d1bd70f0d9b279a4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-goldmane@sha256:37d090964d7b522958b4321522c2d1e4e35341e7c8232f615c2e48eabf54287b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-goldmane@sha256:6614e781093c7c8900019ddb533fe83a1da897e433f6add2307d1d881dc142e9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-goldmane@sha256:b1eaba5986961baf5dfafd956e7ad07488142ffe29da017a0e02937ce4ee3c3b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-goldmane@sha256:d92f7d22da293053891fdca86c7dd5edd2bd9043de255fc6b22702ad376212f2 |