Sign inSign up
Calico CSI

dhi.io/calico-csi

Calico CSI 3.31.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.31-debian-dev, 3.31-debian13-dev, 3.31-dev, 3.31.7-debian-dev, 3.31.7-debian13-dev, 3.31.7-dev

Index digest:

sha256:46243ff4821faab1104368a954bdcece4d835efe392814abca11c237c9a82c32

Manifest digest:

sha256:a3835faf2b175b32c7428a3a903b09f7069b037a4ab8f34d3d09eda064c16c22

Size

30.95 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-csi:3.31-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-csi:3.31-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-csi@sha256:53900e7b10c6ee58db231458925a9ef627a9f88ad7e506d41675186fb0e28ddf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-csi@sha256:6a7178159c74a588214d222b72d74839f328e488baeea90f58bad7f8485b4116
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-csi@sha256:0cd5ab906ef1c5a3143dfca01558b2748174f0b3d00deae37200503ff6a37ecb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-csi@sha256:14838ad152d5968b62db638638e87fa5d5531194c65d233118a667df5845aa7d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-csi@sha256:eef09f395f3efe305f1ec122f2f922a51d1c56360a345ff759a86cd8a3b7eb24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-csi@sha256:0beacaffd08a71990a5003df64b612dcd2b5660df1780ea95a10aea240b6a51e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-csi@sha256:1a5f3845c89d0047b0abcec7a663b6122a7874a2450e7595a4123f38743105ec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-csi@sha256:d3e67e12c7a327b56fe77c17cc75a333fe066ce9520f133db382ecb49ee00f62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-csi@sha256:1c4627c01eb8f342e982f5103acd2f2f6d90ed7bc1ff588c26b2d9dee0e2f452
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-csi@sha256:50cef7cff5b9f7b3a2c419878aa0292825af3280312289e2c616b45082a1c453
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-csi@sha256:ba27451a5bb833d1b8abce55b6904c6a328ee367249183cec16c5ee2c3faf8c4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-csi@sha256:7840b4534d917d0617edb975d2f3723ee55c6d14eaf71fe0d0a04dc8c1e49d05
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-csi@sha256:2b2ba0058a9ac18f32b40cf32c60a1f942e82cd413fcd9d342751f65444457e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-csi@sha256:2dedd075431080b2417ff8d96e965d03680ce2db40bfe13d201d0b5cbc9c33b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-csi@sha256:55ab448f4ccae7752929b750d18c1a4b148378c31fedec38ebd724c719cd004d