dhi.io/csi-snapshotter
8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.6-debian-fips-dev, 8.6-debian13-fips-dev, 8.6-fips-dev, 8.6.0-debian-fips-dev, 8.6.0-debian13-fips-dev, 8.6.0-fips-dev
sha256:0357a8f8ecf5189e4aab520d634a7aa8d1c3d7dc47143a74c2255e4004afe5b2
Manifest digest:sha256:14c55748ed1a72ff5c981a8fad86698e96b59d3eca34209841d39b78c812fa2b
Size
56.97 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/csi-snapshotter:8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/csi-snapshotter:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/csi-snapshotter@sha256:c1f44018453a57fcf90f82843290852247fa782a78ac534b9f96561a6e970d16 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/csi-snapshotter@sha256:19b059ed92221951baae04364e378eec9c93246afadba274b744b3ca51c52e79 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/csi-snapshotter@sha256:4785fa360a3de4577924ecadeb35d2c611bdf312263d84c9864cb353eb16a25d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/csi-snapshotter@sha256:03ddaec9cc36089e80b747788d0cd72a7dfd1a86c7150b36b742edaad24c95ba |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/csi-snapshotter@sha256:817547b73a0d81435bb458288f6fcc9bd9b9612daa16255395e15a98b644072e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/csi-snapshotter@sha256:568626a2bde87d8d761afd5af233f70f31dcf4dfbea43c507e3a0ebbda71befe |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/csi-snapshotter@sha256:e0f9e588576d2a5f203751f26e3884204545636b1e6d8e0485369f44ca3ff42f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/csi-snapshotter@sha256:defe00f0a0232243c4c9947c1e52af4f7f4f4f11bb1fa1c1ad11c5effd9aca5f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/csi-snapshotter@sha256:4d4f03db1b3649b3931887c9bd3fa47f48c8509c3ab21892a7b6424f2c6a183e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/csi-snapshotter@sha256:d3328a67cb4cd58fe2f17d9380ebede0dbf1f6e9f6f24bd8fc21777f5023b70b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/csi-snapshotter@sha256:38ac47b6dbda1deba48f42c2d84c4653b179c6a7680191b6befc212b3dd1f29a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/csi-snapshotter@sha256:dc6e71d88c7cd3012c5f0aed3ba9a45107991e904aaa4c2077b8e7768eadd5fb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/csi-snapshotter@sha256:0e1573e9d0403de368b9b4aea72dce501a657f5bdd8da731a8038a556da2dbcd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/csi-snapshotter@sha256:92335cf6ec7869d8e2cb327208bfc8a1aca7cddb1ba18929a83777912f02e1ed |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/csi-snapshotter@sha256:9aa969fc58abdd98c9556b28d5d96b0f21075b4c3b0a53f772cef841d0455cb5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/csi-snapshotter@sha256:a9befb97972589a7c7f77943901207b709f3e942f35dec8d7d6c4ed189c13fe2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/csi-snapshotter@sha256:670043b11602464a8046220d4d9c3bbf6d34185f6fe31e062534cc897b5f6636 |