dhi.io/calico-csi
3.31-debian-dev, 3.31-debian13-dev, 3.31-dev, 3.31.7-debian-dev, 3.31.7-debian13-dev, 3.31.7-dev
sha256:1d4c3b88e7ba987cf5611f55c22d36f565164e2d746a6a98b0b9026290f839b6
Manifest digest:sha256:0084e91ce128a729d2c0ab614125d615e39bda0e251b574ab61b39b7408aecef
Size
30.96 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-csi:3.31-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-csi:3.31-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-csi@sha256:31209b2161e772392147e52f5b425cc0c2e0b119f74511095d7d6631fb79c81e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-csi@sha256:427e00b5ad50af531a42240078e97c75038b6ec0facdb30212eac5a4715ecc94 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-csi@sha256:76fc49faa31c120eded48883c888eff859413ef8cc18f53436a64cc25d02b66d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-csi@sha256:ce99ee2426f4bf1fb1184ea5f09ba9b45732fcc1d39200f8b73810043d29cef8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-csi@sha256:0f7d09b9ad8904a8adc77c9ec8004550d919c515e59a86f6defca0edbc9ade9a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-csi@sha256:38f08694a9895adbba8d66b4b0ea9736cebf56e2dddf49b4b95e40ca691aa2cd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-csi@sha256:6c4853517259c20e3ae68b43e0e4d579b4a665da02c880e6a3574e76e97421a5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-csi@sha256:f578c4afdc237299e0b999d9679371869542d51e70697a7089249c3f155a2700 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-csi@sha256:59f56b373c80805d946ca39b015e7d01913a38a33360d4f39e7e25a4dc27467a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-csi@sha256:306c7a866e96c8b37ad81eb996741a10ec84e065f1ca7ae7f5389be815ad583b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-csi@sha256:7bba1b6e6eb31fccfef6be5b4c6e1fb48b2de5200651f414b6ec740344bf8d89 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-csi@sha256:14aa515828acf2d9b77a475904e377be5055a9a9bc384d376e1525d578f68bee |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-csi@sha256:117dc9241070f4ab7a071e2919522d8a0f1b530b27dae986b8b63e3c93470eb9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-csi@sha256:ee455e51f562f561d7eacb11b071154a1540aee746a5ab09fd32db672edc528f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-csi@sha256:ed5fa2f101f6d6d2cf0b651b371d3cb8cc9c0de1f5d0590dcad662fcea5ee953 |