Sign inSign up
CSI Snapshotter

dhi.io/csi-snapshotter

csi-snapshotter 8.6.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.6-debian-dev, 8.6-debian13-dev, 8.6-dev, 8.6.0-debian-dev, 8.6.0-debian13-dev, 8.6.0-dev

Index digest:

sha256:83252fefa4b99434015799e3e8199f0e00c5368437151737d62cfc87fe0f5a9d

Manifest digest:

sha256:71a4c6ce3d8cdc944458dbb685375cde6cc239fe1d026486bf3349502f21ae80

Size

56.22 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-snapshotter:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-snapshotter:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-snapshotter@sha256:fb57da66a3d48e1f9e928c0777a0b607cfbe9b4fb7e7bd0e4ee5911a8304ae34
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-snapshotter@sha256:2cd1acdd3cd0f34a20d7e8d29c1630218eecf87026ba17cbbc3fe4c5638e6142
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-snapshotter@sha256:23c4a4894a30b1dab7d9d8085bff62a249d48117873fd5400b88962f95a8a47a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-snapshotter@sha256:ca36cdf30b53c3b45fc008c70e1f20bc023a1743868994aebd7a7e36487a76a6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-snapshotter@sha256:b7c93c48a7237e884517c731b1ea424916ff35b90c487d70477e5d4c6a1e0989
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-snapshotter@sha256:502bedd4015202ad8f8d07421332a206b71746558e292a768ae0a2baf43b0371
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-snapshotter@sha256:3948cd856887da1d61fbd82c36bc1956fb9a3bacc1bce155fadb7954a6567ead
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-snapshotter@sha256:e1b29e7eae80e6d750d0edc3da69f1b500deda4bffca4eeb73bfe82272bcf2fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-snapshotter@sha256:12456f3c1f9b1ce7185566990335d73c7dc114b1bc84226db97570310bb17828
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-snapshotter@sha256:f98bb4e530f7ec0e3920f52eb75b6e72517cb2f335dda24d3d1e2ae849c31999
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-snapshotter@sha256:d46f84dea1fcd5096336ab5c4335b1ecfad38108eb9b8231396ebb1d85f9ff10
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-snapshotter@sha256:49b24d9675de4f8aaede3906a0360b117200a1a7c3720b130c4fb9b6617a20f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-snapshotter@sha256:97740eb204bd4500d05770d0222e7ebc6ef9eba71a7422d052aa8fc3c21519e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-snapshotter@sha256:80fe3a648d793f573891a70b78828840237a9e3f0745d1ab06614e1f93c972de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-snapshotter@sha256:263c74b868d9fe7dac36bce2cde12a4498267ff9fbcb8db1999aa841d7e67b06