Sign inSign up
vSphere CSI Driver

dhi.io/vsphere-csi-driver

vSphere CSI Driver 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips

Index digest:

sha256:92493560ab56fda97dcfe0ce8912e3cc9e5cff30332cd31cf330421d72ee4617

Manifest digest:

sha256:07e379ada3382c405b4548d8c2ded79342165cff53908514664db29eb13fac9b

Size

61.10 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
3
0

Support

Ends Apr 2025

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vsphere-csi-driver:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vsphere-csi-driver:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vsphere-csi-driver@sha256:57ffd6ac4b43c4dd6bea13249f6910c73d0b1fe3b0a9974eb4555a53c9c70f70
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vsphere-csi-driver@sha256:102373624898a389decdced20eeeb05a7e2b56a00d31856422c3240af6233880
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vsphere-csi-driver@sha256:e14238fa0788c9704f5f30f1fa9406718491d5696f7a2d1374f166f12f6f01bd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vsphere-csi-driver@sha256:512b2df2421aed65b6e19a72a7d80a796be91ddee8b9490d75c477c227abeed9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vsphere-csi-driver@sha256:5b9cb41e8025e3fdceaa1524648599263cb683d666892b9b52da2db51c8fc5c2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vsphere-csi-driver@sha256:c022c58f45a32a5d8282b937b360d071fbbe04512ab69beed0738b6df4a243f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vsphere-csi-driver@sha256:a445e176523b58ce64e66c7471cac6d4bcb7efd50c7e242b8eac3e88cb20a745
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vsphere-csi-driver@sha256:280907d568cfacbad01f03286413a9aac2a1011b466b96325c67247eb7c6b2f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vsphere-csi-driver@sha256:914f204fbf50a0b67f964e4ce8c1dcfc3c44f1ca9da5d8338970f55fe816f091
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vsphere-csi-driver@sha256:c6889a96296afcc0e9f3ddfaa348e5470bdc0143d85a5343caec957247827143
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vsphere-csi-driver@sha256:1ef5f51ccfa7a5b427a19f8dfd83abc4cb38d7974cab8d99dc491df9d0b5170b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vsphere-csi-driver@sha256:0f00231a96224b201caeed0b5216672f22feb736a3e10786f548e2ea34999383
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vsphere-csi-driver@sha256:d9682d978cc7e244f1a7d7f39caeb589b16d156216fb6d3a9a60925a40d02a0c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vsphere-csi-driver@sha256:06799556978e4bc38341384844e3ab82bb80ec7c0c70f6c95aa9e65d8485431f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vsphere-csi-driver@sha256:566e504f14d8fea1976b083f2913bc6657f87cacfaa5f1195b0549cc95984664
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vsphere-csi-driver@sha256:066dbc3e2c9841e17532b6228f3a0ce6446f1f19863af6bd55423e2ecc52208e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vsphere-csi-driver@sha256:f4fce265f5d5216c97db7033f694cdca8c0296ebd8b579d7e7fa7155e8bef861