dhi.io/vsphere-csi-driver
3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips
sha256:bd59d055d8089c915b17f9133938cd64e9031a031897a69b3c33942f642269dd
Manifest digest:sha256:d040b5ca1e42c1146df83fd171971b72dddf648e06d985f5cc0e6446f7b76fe8
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-driver:3.3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-driver:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-driver@sha256:6475543494b4951d0506b955a838cea074c9b148595e090e686ca5545489bbff |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-driver@sha256:7f67f346abd21b59166db3cb1f4534789c2c48c9815a7a2d8bfc6aee9049ab23 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-driver@sha256:7b6690e89687a1bf8d7449083e60cb4eefef7b00a112db142698f1a3b3bebd8c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-driver@sha256:0190a4369c07a923e698e7284bf03b29589a3af7f372e32cf797ab1333bc0032 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-driver@sha256:e368c619b9ceabc89722319f951b9c1bd4a0b4e5f64b8b131e906686c3ef8322 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-driver@sha256:8f5a0548640a6116dbb5f37155c04ad0299f754cf735bc7cf568d27f47ec080b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-driver@sha256:52eb1c11fe4a974b721670f443c967dd69ec3c889e0447258a1cfe62ee6f72bb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-driver@sha256:bb1a65557642714470dd054b33c23269c692ebc9466a7bb79e01e0eca96205a6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-driver@sha256:6a075a5628eb74e27e2071dd0a7e5969ba4dd69d7c063448fdbcbe288489e8da |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-driver@sha256:39ba325dc6bca6fb484e005e72ebbbcd48d7ecf9de093549acfca9e0a1f36bd4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-driver@sha256:b1504d8809e7d3d91fb0a053fde7549988c40b008938434a45a2a3d7ad5eafcb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-driver@sha256:8d331bf90707ce88629bdd7b078abf30d7c29e54595254c8d02ef5ba499471f8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-driver@sha256:0fddcba0059f94df83ca5c116706abf817eacdf4b3e55fb47f4e6f4c524ae38a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-driver@sha256:f4b6b3b8881e3bc8f79dc79658506a8372f537a23629915ea024239465876cd7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-driver@sha256:2744fcefe1bf376fc30a1ffea919b92be6bb622a0d56edf5d7f5fb021cb5c12a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-driver@sha256:0cf21f264a21d4a7ffca11ae9d2319ad18886e2d0f3407f49a73bed5fe33bf8c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-driver@sha256:c396d16a4c3662cad283342634a1f5956f265df32a3d089d64c1b83a433b04f9 |