Sign inSign up
Calico CSI

dhi.io/calico-csi

Calico CSI 3.31.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.31-debian-fips-dev, 3.31-debian13-fips-dev, 3.31-fips-dev, 3.31.7-debian-fips-dev, 3.31.7-debian13-fips-dev, 3.31.7-fips-dev

Index digest:

sha256:57f4613ea4094853794074fd42637aaa17de83c7aeb5c8cfd7be8cea74e2e57f

Manifest digest:

sha256:5c49d0eaf03297930a042c39626a3114dbab4597b8fdb33e915cb79eb1415789

Size

31.72 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-csi:3.31-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-csi:3.31-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-csi@sha256:777ec5d493e8f37ef5f2406edb69accac4652ab24ed951c38d76d81c75fbff93
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-csi@sha256:de2629285df32d95dc0819cf87fe8246629e639bb6d7c013267134ef315170dc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-csi@sha256:a7b1b47402974bd22aa4b011051c394e59c2b39740a0f92341e04a68a241ee31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-csi@sha256:68c051c0d740de8288a9303783e7a1c3f0b7a3976aef9cd9bdc3cdbf0f987389
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-csi@sha256:bd02d33a216448bd6fc0d9fd45d2c1a7bc32a05bc71248b50e643b93f5b10494
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-csi@sha256:15d0c2fa25ae9d79b7a82e89ab729551efabb6585074cda7fecd853d4d46e55d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-csi@sha256:eed75aec3cfad0fb7e2578127eeba9a02b854c81c8fc360468e8634e68f521b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-csi@sha256:bf48a674e18c27a2133b0b779061f7ad5a8085681d25b9d01b6b91ade767fa57
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-csi@sha256:317f759ce5f08362faafeed5cb0082565964fe0724aa8f56f14e536811bf56fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-csi@sha256:4e98edbe76c656c7b658dff10aa0357a90b95cea77e4e3084a9dddf4617ded17
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-csi@sha256:bff2c3032296f3154e091074f8e86902acc43e3676fad2239121a5c64e17fffa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-csi@sha256:cccea7346983c482b6d808a76b5e16f3072a8645f560de293c33081e0ceb1ff6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-csi@sha256:bf3b844e5b4b4bfc2ab140f0d8d768c7d99edff92e894b34a788b3207c41b709
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-csi@sha256:59c1e9ef4bb25560f971a2eb3091a1cb88ecb81eea38f990aa82f925b98e1f8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-csi@sha256:d6b7089aa046caaa4b6b3603d634e05cf9e43b054bf4d5eaa6babca4711c6c7e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-csi@sha256:4e31d23d3581d84558243c3c4e505e4e4aa7f03fc1ab7913302f6d36db772bba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-csi@sha256:7901c82a2247921ed1baf874c7666c3305b96954b61fcb187e714876477435c2