Sign inSign up
Calico CSI

dhi.io/calico-csi

Calico CSI 3.32.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.32-debian-fips-dev, 3.32-debian13-fips-dev, 3.32-fips-dev, 3.32.2-debian-fips-dev, 3.32.2-debian13-fips-dev, 3.32.2-fips-dev

Index digest:

sha256:53c9e9bc6399606cc3e1e33304b8143665789dc74eceecf3accb277e09834e2c

Manifest digest:

sha256:d5b6f31aa7424b12b06dba8506dc4e36cdac13400d6ae139862f8b6ce66e4529

Size

31.73 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-csi:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-csi:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-csi@sha256:c0a9f15c48aa80887845c43392fc0f1c11aef4383ef94da13b92e7bc980cf459
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-csi@sha256:bb11b2bbf3916ecd4d140215dcc9b329376a6190d382ef9141171ae2b307b947
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-csi@sha256:f58a7ecff10bcda6712a7e02259750599de3e7c8f1d4a24a61753faaa62d457a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-csi@sha256:f77a2182d6134f7658852da9ac5c1aa3fa688f8c113c1cb745d44b801d7d1aca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-csi@sha256:cb9a7c7a9fa3476a0355ea7720299cb4a8bd7814b7433c130d8be4c6e5b5c60e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-csi@sha256:065f00554c4f6fac650b523e59d52567b808715e9ed3f7442f5472ff8251c2c6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-csi@sha256:0b831905348980ae5d8ed661cf662f432ab2c14205b2484a00cb541b206d3dbf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-csi@sha256:6b5f796b6f71adc5194d1db624f4b680bd6918691d1e80aa947abeacef062833
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-csi@sha256:4e5c7f73f2563d98ec09adbb96a654214ecae83bbef8331aff8a4499821d5151
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-csi@sha256:f78f51a99b20a51321a369bb33c19e488785c734efe09fe29af750726532f0fb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-csi@sha256:d1cca27e7e7b080506f94cd287bf7e855b4c8000323cdef14066eb9f6a74e3fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-csi@sha256:9fc7698cc0a2e9c7d291c97922c7b650dce0524a577caf8669ece308fa7143bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-csi@sha256:d7bccf347162f145a4e1c5abd942108d3aeeac0e1d57cecbd363852a83c3f6e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-csi@sha256:cc1b15f6032525fa022080914930a87112b3cb3cbe8f8158044c4ac3d02f4b73
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-csi@sha256:a21c5f719e0a4f0017ea75bee2aa1922e673562664163bedff6dc2b2612347e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-csi@sha256:bd0c7f84457039312632d90ae2dc725920fbd89841caada826c1bac7f010ed03
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-csi@sha256:3f885190e275b9e6b18c5429ee61efb62bf8fca79de568af6ad2712cd15f57b1