Sign inSign up
Calico Goldmane

dhi.io/calico-goldmane

Calico Goldmane 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.32-debian-fips-dev, 3.32-debian13-fips-dev, 3.32-fips-dev, 3.32.2-debian-fips-dev, 3.32.2-debian13-fips-dev, 3.32.2-fips-dev

Index digest:

sha256:59f9febd72b5fa65145e459a71cf6a7860c7d64c8a0d517ae55cc99bea5a922d

Manifest digest:

sha256:d46ebfba2a124542f84da8499c72766d9fa4179bba34b2b5099213e6746c4282

Size

70.70 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-goldmane:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-goldmane:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-goldmane@sha256:711cce591156e1df5255c3d2bc59f689bd3b188fb736c00c3a394cd85d57d97f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-goldmane@sha256:e5b4de5aa5b9b063081ae0a322f8ac27dc429edda982eb4e153e2b2ae168f05e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-goldmane@sha256:06524921c622434e5ef724dbef92e0cabc28394f487b01a900b4bcb1e9ecb537
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-goldmane@sha256:f1610b2d53e50ca9da1887e14636915994c78ff428feee08039d505900634bab
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-goldmane@sha256:6022d3bcbb63741fcf30909813dfafe7dece1480af279b1423542f0269ac1529
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-goldmane@sha256:18c1c3b11d9d6e6e2a688831aaa170dbba288c3a350ac706c3b049c09007e165
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-goldmane@sha256:87ba68df49a12440b5a6b1ad0b833dc7324f40a2a314751417f3c41aa9d82d2b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-goldmane@sha256:3a109c473afb93c8ff2928ee10b3c828456fe478dfbf18ff3512c3e4928a17f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-goldmane@sha256:48112b5b42485333362ff2b969341ddbab5362deabd78d479c5048f51cba91b6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-goldmane@sha256:19527d4f8ffbdd9aaec68276b4c207d7753b79c55875048439ab58a55bd92edc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-goldmane@sha256:23ed300856a2d034944b5ec5dd6178eca109d46e7e78eb61ba3b225fd840c46c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-goldmane@sha256:a80d14d70e8f6419a76f3b0bae0e44e7f3b09dea0bf386c9965d188336284d76
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-goldmane@sha256:d82090dbb40e55108b0dcbcebf79df771927935212c3e1c38b7f425707c8954d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-goldmane@sha256:52a8de61fafd5fecf7020dc187fca24ca0ffd1c0308a4a2c2cb5ba3f89ed5648
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-goldmane@sha256:f4f45dc6d6f4ae2fc5c3106c6f996187e37f1fdebef80720a2814a3138dbe668
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-goldmane@sha256:7ab2503092c7e732b6feb182316ca74b1d74aa3a9dd796f2a4cab30f495380d3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-goldmane@sha256:47e82f894065cbf47b17333c5299b519979a3edb3a33f7932214c643de3f1bf4