dhi.io/calico-goldmane
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.32-debian-fips-dev, 3.32-debian13-fips-dev, 3.32-fips-dev, 3.32.2-debian-fips-dev, 3.32.2-debian13-fips-dev, 3.32.2-fips-dev
sha256:59f9febd72b5fa65145e459a71cf6a7860c7d64c8a0d517ae55cc99bea5a922d
Manifest digest:sha256:d46ebfba2a124542f84da8499c72766d9fa4179bba34b2b5099213e6746c4282
Size
70.70 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-goldmane:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-goldmane:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-goldmane@sha256:711cce591156e1df5255c3d2bc59f689bd3b188fb736c00c3a394cd85d57d97f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-goldmane@sha256:e5b4de5aa5b9b063081ae0a322f8ac27dc429edda982eb4e153e2b2ae168f05e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/calico-goldmane@sha256:06524921c622434e5ef724dbef92e0cabc28394f487b01a900b4bcb1e9ecb537 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-goldmane@sha256:f1610b2d53e50ca9da1887e14636915994c78ff428feee08039d505900634bab |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/calico-goldmane@sha256:6022d3bcbb63741fcf30909813dfafe7dece1480af279b1423542f0269ac1529 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-goldmane@sha256:dbff6dbc6e69b6de827799c41d39f67501ac314edaec6557dac0bbb725a490dc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-goldmane@sha256:68ab01b595c8e162d5e4f7295ca4b6e5bfe1ad9cf7cada94e331256bb3a9c633 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-goldmane@sha256:3a109c473afb93c8ff2928ee10b3c828456fe478dfbf18ff3512c3e4928a17f9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-goldmane@sha256:48112b5b42485333362ff2b969341ddbab5362deabd78d479c5048f51cba91b6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-goldmane@sha256:19527d4f8ffbdd9aaec68276b4c207d7753b79c55875048439ab58a55bd92edc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-goldmane@sha256:23ed300856a2d034944b5ec5dd6178eca109d46e7e78eb61ba3b225fd840c46c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-goldmane@sha256:a80d14d70e8f6419a76f3b0bae0e44e7f3b09dea0bf386c9965d188336284d76 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-goldmane@sha256:2510ad8d682c03afa838369844f98c77482d2ee0ce65285712932f3a9ac8278f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-goldmane@sha256:52a8de61fafd5fecf7020dc187fca24ca0ffd1c0308a4a2c2cb5ba3f89ed5648 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-goldmane@sha256:f4f45dc6d6f4ae2fc5c3106c6f996187e37f1fdebef80720a2814a3138dbe668 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-goldmane@sha256:7ab2503092c7e732b6feb182316ca74b1d74aa3a9dd796f2a4cab30f495380d3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-goldmane@sha256:47e82f894065cbf47b17333c5299b519979a3edb3a33f7932214c643de3f1bf4 |