dhi.io/vsphere-csi-syncer
3.3-debian-fips-dev, 3.3-debian13-fips-dev, 3.3-fips-dev, 3.3.1-debian-fips-dev, 3.3.1-debian13-fips-dev, 3.3.1-fips-dev
sha256:afca508e690dc3dc7a211450e3fc3400223ca2df152c5c2c0ddddef0954f79d5
Manifest digest:sha256:3eebb60306c0d2d448aca706b53061bb95bd8f8acecc1c3243b9d485969041d4
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:90c1a40acb49784a421e4aa820fff1a3011208390078a976eab9e4797e9b5c9d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:1824c7f66481b95b3650ee4b052de261a9ef8fae118c89c89027a6fabe3f2e0b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-syncer@sha256:c1ff73922595624464e61587891b9eb73a6a0f7eeb943e1c39fc5193dfc981df |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:1793eb48c8f62f429cd0026b795b350b1f970b62740cfafa79bd2b04be48cfdb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-syncer@sha256:486584187397a1a10292110371367c77f5a94045ff94ba3089183ce4402ade2c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:f5eff21a7cb6ce8fb5d0fc5086258a411d2726eb5c58b451b37444e1b990762f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:e0baa4955926cd8cdfd0a75495f66112004fc5301561d7e31e1988d8f1a6b0cc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:a59adb48616da2018e7705297d8f6dba0de116d3ada0dd4fd5c0cf065c002004 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:a8ddba44b87efa62e2f0db0cdaa0e80c1f40300b36368e8887a0e5224331f61e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:c9be6d11021774ee0777052c948186438350d3ea7ece2992254b7e5f582f0287 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:032f53b79049e16a1c2fa8a33e22c9e6e00b1985bb6d14e09b74cab5c1c11c68 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:52c60caf31474e691cd423fcb891a89e52e8edb43d6c89390ded62402b35b462 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:7d79b668bd54ace7432f758cf0c3184d58ea13623e012c405a623b1c8843ddec |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:328b23ff2f6e7dce090690ce99223f3aa3b3bb51a38827355271e82055ec3a94 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:51ca88e13b5606519b5d10adb8e16e73df0b1804bb52bc391c3fb097ab18c545 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:0e585e8f3b488b4fb7bb1ebd88c339feffa7c28e53d4e094303d06dd676ab17c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:5bb31abfbce53bd66ea736c5afa0ca10651c555e365542414663b4b86f5101be |