dhi.io/vsphere-csi-syncer
3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3.1-debian-dev, 3.3.1-debian13-dev, 3.3.1-dev
sha256:5deb7b51027813f6c55c4a13222c9c6b89830e5304d74bf45ee8455fb8682bbd
Manifest digest:sha256:728d88d409fbb52bbd9fec14c5b145ab5dfec0207dce65f28efe9a93343fd061
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:8c5bf2870a563e74437675b0d2ce10d5f117bff0cb21e5c46ad05b0322268b42 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:05a459314c9641bad605620e06e49814565c664beecb09142ce01fed15f8e8c6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:add1ff42832bd05587107dcc12888d42258efe7e8b47c63b1025a145d7b63284 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:817ca3267717f60b4dbfc531c3dad39cdb3f1c54c9d2d0ad5bb39dd7124e95c2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:b8d83f335ac2ebf9ebe725421192425e4cb3dd5eef3d0ad99f844d205a4adf63 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:b9d1d3fdcf20082aa11d15198917f57bea878e336238d6a0fc2cafe0f62c68b0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:f59608e2b16f9dba83b20e4e664d91de66ad0b56c9e4c0f0b0b0ba2879e44205 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:632c9801375b5ca079c06f06432bd5d369f16b439dfda40fcd8a529dae4934d1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:8bc744627aeffc4a8f03e6f0ae70af301db4fdbceda2cc29f47d269eb1f85efc |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:a61f61adb0be4a59f95077fb2b72c77b16f2efc13b896fa760ec83e3f8e1d212 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:2e51b703131b9552371c3b2331aeed95312d0963e85e4eda0e5069a4ef29e2e6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:de43d45a74fdf8a587e39fa5a70d4cfa3943557424fa3ba50934692e61a221d3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:2bca10a329715b394ab2e51d03dfdba869dc4180988e7f0d9eb6f941d19d1f00 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:d88c020498c012febb354c23ad52e9e5c26ab6158424bf8d47c6df93e1bc6801 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:94178cc4e239de65eda44450c7ae7fc0a5ba530d81903c6c62cccbedb0e9161d |