dhi.io/vsphere-csi-syncer
3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips
sha256:4af53037168346c5f5bde754d53e245af590cd2740c4cebd3144ef12e54793b7
Manifest digest:sha256:36f625043cfca48a87e1f6e4cba66494cd691479a14cd139a6e0ee873e889cc6
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/vsphere-csi-syncer@sha256:22c1777fff31a3711c9d7e45a9b65cf6d6a593b4ce6e0fad9521263df81b0b06 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/vsphere-csi-syncer@sha256:5bf4b7a30a66da8952e8032de38a0a096819c5378178d3bae055556cff03b7c2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/vsphere-csi-syncer@sha256:ef477a936cbaf940b5ee76a5bab61218be5910142116254f59b1f2fb8761ac91 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/vsphere-csi-syncer@sha256:356a34ff03f57d31258b5446776463b6910b187b6ce92f54dc17a3932c72d6e4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/vsphere-csi-syncer@sha256:6e4066ec96c26944721ff4b566752553b141afe93f620932edf1cbd759f2a2c4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/vsphere-csi-syncer@sha256:fa8123ddd746f4ed71111d1b044e7a2a8bab71ec3a21750aeb88ca698c339135 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/vsphere-csi-syncer@sha256:0c9acb91a761ef0ecaa331dda3f39c3505064752b1e857971bf2d272ceed67df |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/vsphere-csi-syncer@sha256:2e54c8632d8c774984cd520e65c6c8e26ddfecf76d2a7c92b11107d524aac349 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/vsphere-csi-syncer@sha256:8de25c122a0cf14c159c4ea1173e465f10ad75b93bcd0086235530953584203b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/vsphere-csi-syncer@sha256:f872e82a42c0d77aa909cdd5213733fe7dbe0200bfa63dc3f280800d1fc82de7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/vsphere-csi-syncer@sha256:76f735ff924f7cef0cc47a453f4ec8f707c685f826edaf1e09a38dd43c968a00 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/vsphere-csi-syncer@sha256:150fafe551f41bfce99dd8ec11228205b0cda391f3ff72e6422fba267d26de41 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/vsphere-csi-syncer@sha256:4f7b09dc6c190c5d2cfc3d45471109e6223aba956b69d457eb4400e5d0271d2e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/vsphere-csi-syncer@sha256:e3b7fa55a899352e8e8e7bd0bf175524e2c39e7f16e72f2e232db532dcadf652 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/vsphere-csi-syncer@sha256:965a32a1d184c2671e8a994432495482596b7ef1556241a6ae2bbcfc1b44be1b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/vsphere-csi-syncer@sha256:60fe1dc4ce3c21e8afa045338d1e145ba5ddf8b8b81f9a65229cdf881e63dbcc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/vsphere-csi-syncer@sha256:97d02c5e21404df81195cf89fdefec7163060959b09aaadfeba03a2c9491af2c |