dhi.io/calico-apiserver
3-debian-dev, 3-debian13-dev, 3-dev, 3.32-debian-dev, 3.32-debian13-dev, 3.32-dev, 3.32.2-debian-dev, 3.32.2-debian13-dev, 3.32.2-dev
sha256:48c40d2bc76bb715036562a50c9125b95035c03418f1a5425c66b319c3715c80
Manifest digest:sha256:4f0eebc49c511bce99367122d2c4daea99dd6dc43ad3e4a4684e9f9d8006e825
Size
65.66 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/calico-apiserver:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/calico-apiserver:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/calico-apiserver@sha256:f6ff7c6a859a236c498748fa83ff8a3d8b386a355bbde346cda97da4341e5373 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/calico-apiserver@sha256:b7b3387fcd957bc4d78e88bf886c14010323533cfb54b3b7637f1664bfbd3118 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/calico-apiserver@sha256:fd90c1e596eba1f10a4db7405fba0c5f17550a8f62f1945a4f46e52fd2b07d94 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/calico-apiserver@sha256:ccff3838a09ef8971df1b9a0809e2a21579bbd9776fa5ca79ef100656fdf3c40 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/calico-apiserver@sha256:8c0dd610088fa3cccaf4b85d8ef9e5b257cae885b1f19c3723d10059d2301ef6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/calico-apiserver@sha256:517c7f56584536a51da02c6479aec67b314720728ab233fa9467092c0b3d00e3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/calico-apiserver@sha256:31579433af7cf1922f8a470b58e10c3ee5c4c70ef41aa9d296a67fb631e11c6f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/calico-apiserver@sha256:d3c00532036784b48e3b403215731ba86a1d58fd7e0d6244f9c8e28a5afe65e9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/calico-apiserver@sha256:035f0abaa8795e3ff460a04951b75df16d897c75563d91556f6eba72403423c1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/calico-apiserver@sha256:3277031b19c0c9216604121ab7113bf27620d0cfd3cf46b6523896c29b533f7a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/calico-apiserver@sha256:94edd60284fddfabd3c8e0c950d3ac39f40d8f9675e31d11ed8cc78a091f84f8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/calico-apiserver@sha256:35706a82e8b13a963e50a45e24f3fc44e415a0d7f95f10f06b0492b2e29b3412 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/calico-apiserver@sha256:fb71071d8602f0acd2060ab143e90afdeb4f34b272e7db6e03c0ed0aeaffc9fe |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/calico-apiserver@sha256:7ae85febb196f855b6577221e54731055b02d5d4272e3c7db991c3dded5e4b9a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/calico-apiserver@sha256:36e339e4a97eb9fbd4131adb23d9354775b42bfcd4e3a6752cc33a30d3a62171 |