dhi.io/csi-hostpath-plugin
1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.0-debian-dev, 1.18.0-debian13-dev, 1.18.0-dev
sha256:4f19affa1d483874cc4531bfc5288a232284ce63e5b838ece0c848419e4c7e2e
Manifest digest:sha256:9ee705999538c55d5b97ab2ff236c086a8d4cd4ced87f10037ccc09efc694cb2
Size
32.78 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/csi-hostpath-plugin:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/csi-hostpath-plugin:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/csi-hostpath-plugin@sha256:b320d143252a976f39f751a608a999ca0fceec0459a14854573bdc0006c29984 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/csi-hostpath-plugin@sha256:1da40d3fee2aca3fdcfce8f92bb43c0a26c5e68eb27ce4d893a26a382c03e983 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/csi-hostpath-plugin@sha256:5f4985ef2859390f763ce856fc5a6b070b45c52fbbbe7fdbe7b9328355424b9e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/csi-hostpath-plugin@sha256:9cbb258bce78531116a7fd52f35762c122e973fd2975e4461f487bc4d89f57c2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/csi-hostpath-plugin@sha256:79b44305f5ef3158703723f7369fb5e6f0c5241509a27fc763326af54b1d1ec9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/csi-hostpath-plugin@sha256:5d947cacfa1c0da9de5cddd11fe5c1b720465b250d59dad99b2f4ec79ba01a72 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/csi-hostpath-plugin@sha256:1a949251d44a91a2d9ff3c8b0df9a528149ae2eef52340661a5ce7ad99b27710 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/csi-hostpath-plugin@sha256:afa810ab0b9a45ac3094511d54454b0a1c2f020a235c4ff712539efdef137ad7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/csi-hostpath-plugin@sha256:c3480115a2d195ac7db5e0ec6747df822c7ebcecb88cd3e63eaa809b9cb6c014 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/csi-hostpath-plugin@sha256:db29dd54dd7b0ec554d629a702f8eebcbc4efef537cd55b640e30139b7e33e3f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/csi-hostpath-plugin@sha256:62076b2468d4b1700b345fa84b431cc9b37f15d81253103f123dfb14f30391d5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/csi-hostpath-plugin@sha256:22a33f467d619ecf670857be2968830439a5a1d6eabb986f53667640354df939 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/csi-hostpath-plugin@sha256:0d16396965b0a87b2760763281628ff3626f105f1b83881738fb07fc3544c9cc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/csi-hostpath-plugin@sha256:8e5464b07acf7b5dfe5eb20ae34cbb26d35c4f23db036de4d36a3be97be3c6b3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/csi-hostpath-plugin@sha256:f1c8b137070c32dc760733f2e15a5c9d0543d82caac68b788e3a4d684c24d4a2 |