Sign inSign up
Calico CSI

dhi.io/calico-csi

Calico CSI 3.31.x

CIS
linux/amd64
debian 13
Tags:

3.31, 3.31-debian, 3.31-debian13, 3.31.7, 3.31.7-debian, 3.31.7-debian13

Index digest:

sha256:244a7d37a963f72c9a4bc862f2d803e32876297a70911e79dddf0621ace81251

Manifest digest:

sha256:9713c5c99d3bb2373fde02696d0e98c34d5ddd743e070dff0baebf2d4667bbda

Size

4.63 MB

Last pushed

5 days ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-csi:3.31

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-csi:3.31 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-csi@sha256:c6586cb6ea9b50af5f7f9051d39bdb980af63a3e2df37c635ac0a95dce5f50dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-csi@sha256:4cabd2a03d42647e2f4bd566cd00d58a9077b187fd3464a0689762395dda3e26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-csi@sha256:38f49c8973e39cdaca38aaa30e8c76796f812724b52e3922c98e3135654b0a6e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-csi@sha256:04babace56ca2e0877298b0bea8dd1c3aa446e84264417ba00f9e540e7479d90
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-csi@sha256:6cb7beefe342fa8236a68a5f14b97e848a1a56415d5f608024d33351eaae654e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-csi@sha256:514830438344189768ffca38bb7c07c378674fbac39b446349036e3a59b88f42
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-csi@sha256:616275788ac539223ea136e1074dfc3e63cd8b07a0ce601a09b3e9dd5ce2b44b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-csi@sha256:4ba77a3bc54d60076f46a7053a9ded081c78de8612b917effdc05c07f250628e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-csi@sha256:5392a580b896ba0c28722b8eca694f52470822380d3f692f7ecbe4f437805cea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-csi@sha256:fcac43044f893e075b188d2d1624af9856a89e93fb3e14d5f55d59608f8791b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-csi@sha256:bc3d92dd948ee83fa891924fc0cecf7c265526fe4b86f6f7dc7588abd0d431bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-csi@sha256:e569c31804bdbd94f72d82041bad81a3c1acff54295857ca4305a40f5b0847be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-csi@sha256:10ce8a3266b28b4215dd76ea98b68d1e6a5903f65a0f948fb6d5d594b13bd325
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-csi@sha256:412d46e7449f36f1a0649fc7bb6736d479cdadbf217a8c2623b0695072f2edad