Sign inSign up
Calico Whisker

dhi.io/calico-whisker

Calico Whisker 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.32-debian-dev, 3.32-debian13-dev, 3.32-dev, 3.32.2-debian-dev, 3.32.2-debian13-dev, 3.32.2-dev

Index digest:

sha256:9bc43c608d4c60e6585b21a710018934534ca820be80675fed5dd21aec32394e

Manifest digest:

sha256:f506587efac8777ffd781574552e51fbcefffe4313a290c5e5d9feb4c9be8ac4

Size

24.54 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-whisker:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-whisker:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-whisker@sha256:4e1ec2b8392fcab8d3f7e7982481115c8cd6be909a8f8b08e6ecd79a1f5b0029
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-whisker@sha256:4d3082454900bb2f24246a1591419ef7a059d97343dce10ba7a4a1d7a0b246e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-whisker@sha256:4ce1941d24daee773b9d7b9f30a6dbf26e96269b57450a0213d5c338a22a20d0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-whisker@sha256:7913e1465cc4c7a2347b68c6636442394739ae1b6605e0062337635c781f8aa0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-whisker@sha256:01c7e30ae661e779f10f1e793cec344719820282128c8a0d703250ec7ca74efc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-whisker@sha256:3c9c10ea5649d236a5465b4f0c33b90789ffeac172599ee7427688a21a3d6ec2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-whisker@sha256:4b469397bcc460a839db68e897779963a1b9a5092afe0e842760194aa91cf147
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-whisker@sha256:50ade02638ec4ece61f4099af051c3b383854c4c5d85e3a9c19a37da828a8456
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-whisker@sha256:36992509f4d238fb345ed657bb26567c743c9420c3af7da3a79094b3e98741dc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-whisker@sha256:106c6dc21efafeea70731028f063f1986fd12a96f3391d1bd2a81b56992241d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-whisker@sha256:7a31285091ea0689bc78cbf9dd0d3ac0d45a6490ab9c264dc1785fb4cdf6aa61
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-whisker@sha256:debd15ee9b6826ae70faf4ecbadc94632f523b21cfe5df375f9a2523efefe141
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-whisker@sha256:7dc1914b2d21c79f3d956f0f65b324c8ca8f0c8a9391d40ab46b80e0fa110bef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-whisker@sha256:21f15fa8e8af60f5e06a72a878f406d4421f4940598cc176bb66b9fa14509955
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-whisker@sha256:09378c0226ac0854470f240e17aaafa3fe0d48ca09128b55d930969849492024