Sign inSign up
Calico Node

dhi.io/calico-node

Calico Node 3.30.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.30-debian-dev, 3.30-debian13-dev, 3.30-dev, 3.30.7-debian-dev, 3.30.7-debian13-dev, 3.30.7-dev

Index digest:

sha256:f08db74c1e9a9b3945088828da435492c38d23a814fcb9b71ae56831a5e85c2d

Manifest digest:

sha256:86ab55d421b3f31670cd032c6cbd136c05bf1a0ad6ef4fe1d4bdf76bfeaaa85a

Size

91.33 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
3
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-node:3.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-node:3.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-node@sha256:16375d309cf8a03b5481a2182cfc9409ffb34cb9bee606c6bb6dbb2d4252149a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-node@sha256:39b3c05c90ebee1e21790755d24b227d5d8a6a7b1816fa4d1a17f90fc8d3f037
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-node@sha256:01f1ace3010cc4f84bdbac31f458166fe1f1f96a2216754ccff45ffcb5e52764
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-node@sha256:0eff8385a15055db4cdf748ee0fd00629d545f3c466e03ec8ba35d0f156f9751
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-node@sha256:24efd291f4ea34f84089bb27694e598143cfa6d51e90b235eba3f6b706f1f756
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-node@sha256:a137ce435cd77904dd224b6fabb8476fed814e21ea480303b7fba71f5e19eb95
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-node@sha256:85bf0d5777fafb951c929e87aa72a2da6b132c9abf3524d6728cc72b60247bfa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-node@sha256:add721c45010315eda717aba12662e4c17ea39ffdd974e52d4e33f1eab84a4f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-node@sha256:a51b38b45c2624a95b46f94c5dfdc3352c02b0e357b675ec5c588bd4045fd4ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-node@sha256:ba9e3fef3ce50981715b5ab37ce2e44d044de556d0110e83118cf591ce94f966
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-node@sha256:4107f9ce7df69f1d30364634283e1483197765067bbcbf4519d2e9e3dc73ad25
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-node@sha256:acb89d5e006e5a69ff13bb0034133102055d387f561dbbbe944d805dd43f40d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-node@sha256:beb8a297af493617f2c5b0f2c0003481f8ac34b25d7849eedf8987a631db62f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-node@sha256:3dba30e73f5d336d982f26f07cc43cc0b01c01caf1bca92f43d27b691041aa52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-node@sha256:cd5ccacdd65414470925db4bd656b6cf7878c3646cf3686409e2dd9dd45b538b