dhi.io/vsphere-csi-driver
3-debian-fips, 3-debian13-fips, 3-fips, 3.7-debian-fips, 3.7-debian13-fips, 3.7-fips, 3.7.3-debian-fips, 3.7.3-debian13-fips, 3.7.3-fips
sha256:5e6e069ba589df8713d15929e6d6f53377a8a115ebf38afb9df4e3b3a3a33954
Manifest digest:sha256:90b3d1441aea80de4c4681848d23762c65e1e60043dacc64c96f3d53d88653a4
Size
63.28 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-driver:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-driver:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-driver@sha256:491491f40995793357f335741453268cd3ecfcd8e6dfc6e06efab37034bba5e6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-driver@sha256:8e95187dd6d8106db20503790352f71e70104f60d5930d68e1103bdd5dd6fc91 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-driver@sha256:b7150955cda9c988763809a1034214edcd2fd1649ea8d2decdae52ef311cfe72 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-driver@sha256:33f07c814f0d2bb090a3876b9da6fb02b24e5e89ea6c8eb3023f942e002c2318 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-driver@sha256:b2b47a2936569d276cf981075d0418ba560a75d35c91b6f118ca42316abbd913 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-driver@sha256:a8f9117ca10c8ec8a6001f5ea9c64652b7a8ac53356ff03aa0ecce9a2a745022 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-driver@sha256:8e130b9c38d02f05dc222baff7993b479b04a1acdf2b1038340bb27a9ec7d4ef |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-driver@sha256:d9f2c4d4d91145c83f699292c0c4b950bb12d54e8392999e46d6f18c976f9462 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-driver@sha256:a892fb366ea7ae9436bf584a12a86286f5f2f3e5ee104dfc345e14db73ca8b94 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-driver@sha256:9c0575a55fa2456ac46b7367c2e4d1bfe0c0372acb73344635a112ead5ac1ac0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-driver@sha256:6949661b9ca452f2cb1fb19804e52001893de17d80ba2ddc75d12dfd997a0955 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-driver@sha256:17d8df42e2cd23924fd79313a0ffc021c003b476c8169fcfd023816d8f1e26ee |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-driver@sha256:5b9cb424a8386a3fb6cc40a372626c079f148b6245a33af4542a19231c65497a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-driver@sha256:13d498c56273fa350cdc6aeb242e7ecc20f01d9196a593e144f96b1b2724fb6c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-driver@sha256:8b41aff0ccaa803e4a1373d98a9f7168ed2e084d3cda1b16b2cc0448a6f7efa8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-driver@sha256:1faad6fecef186d6e5899d59b75172377f22848c02a79e6ce1d59d7bd26fa5a7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-driver@sha256:032cb2663cfcfa61039bbb09327723681d5145fbe625b44bf36c25493b92094a |