Sign inSign up
Calico Whisker

dhi.io/calico-whisker

Calico Whisker 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.32-debian-fips, 3.32-debian13-fips, 3.32-fips, 3.32.2-debian-fips, 3.32.2-debian13-fips, 3.32.2-fips, v3.32.2-fips

Index digest:

sha256:45eba165fe111a9a7107e4a9a5a247e39cd4d6a5c2925daa42acbc22c557a400

Manifest digest:

sha256:4201412836877c7fa296ed14c0afefd7627e4da397978b304c1de6a26eaec6de

Size

13.29 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-whisker:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-whisker:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-whisker@sha256:c0c000a95bc25d142a07c6944ede6c1db11ae269c8c2c5bc2dd7e69e7f033acc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-whisker@sha256:b034c37851c6ca2c0e179c0fca08f3dd3abda45bf0360fe43c9ef72030c69695
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/calico-whisker@sha256:da405d081b8a01a6cd3757358d20cdf71ee9b315b14ea0ce80ceda78ff8be118
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-whisker@sha256:c204d1024cd20b790ac20f32f7fde4510f97b6949e3edf92426b0a051d0e9f77
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/calico-whisker@sha256:643efae8183bae795eec17b3fce888bb004c838f5d3fb1d56d4847c9e6d3dd4d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-whisker@sha256:c2921a4d0fb0f925e4e22044268c74e6878e4accddccbffbf56ff05f84be6145
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-whisker@sha256:761ea2d91d782d03c1b83a3d810ea1ea23bf434b78fabd91bf062b6851f643c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-whisker@sha256:c991d8dd5cca48950e1f144b17120d4627f7d6f72ee4b4b4d9021f588b2cc249
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-whisker@sha256:637a3a9697ca0d2bd19522d2f50e5b77ae0d0c73a0b23f8252718744610987e6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-whisker@sha256:96b0d111b474798fa5522898f6f55573020b7ece4cbe2ef02372a63ddeca7796
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-whisker@sha256:2e6233abf0e910d7b7e3e712497e37c5b4dcc7914d14fb96bdfd5dbd05efbd92
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-whisker@sha256:1d11d4c70bb9f4b2d236e97e67bb13ed9c6dcab890788d769c661653a396f1f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-whisker@sha256:574550e00ed1513224329e4f720b5d428d8bbb85a192cfbb2e672050cb8f4b71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-whisker@sha256:6f9d021115f28572b915df6d654aab26801ec7070ebd19c891d2b9436904a5d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-whisker@sha256:81a8a147bdf30c1571974a2407d05d6e8d69bd487b705a336bfdeca85f02493f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-whisker@sha256:a762acbce06ddf7702eb8f35f50fbde2bb030c5f53a9cafe456b503e9a897323
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-whisker@sha256:9a6fe6c8a0fe07311152c0765f7542fefe323900ee6ba216b4334258b4b2ded8