Sign inSign up
CSI Attacher

dhi.io/csi-attacher

csi-attacher 4.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.13-debian-dev, 4.13-debian13-dev, 4.13-dev, 4.13.0-debian-dev, 4.13.0-debian13-dev, 4.13.0-dev

Index digest:

sha256:be9667d15d0925f312843189853fecccf18ec985d9b8162bbc3086e10bf83f1e

Manifest digest:

sha256:ff96223e9bd0f3553bf02b3cc386a715ede68ac6199d4f3dd3794064729777d4

Size

57.60 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-attacher:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-attacher:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-attacher@sha256:1e71eff95e6735aacaae7182b33efbc0752e51d390b47e803795fa4b472e0b22
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-attacher@sha256:1028c4a0f80c2f5338b2a7e92c72a9ac9bf2e17ec3c53131eeeb25b173647056
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-attacher@sha256:101eeccfa1c28d8195362e110b5b85ac5ebc0c09f696c2d1dcd11ebfef8a6814
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-attacher@sha256:72c80b1c47343a557b252c563967b98b03ac485762a1da8ac3a0149d2726ba56
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-attacher@sha256:9e5b6962dcb78f46473ab4914fcf0b1392b5059ca9ab80e267a8a7e5128e2f0c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-attacher@sha256:661750db352e20fc2d150e4ec1efacc75418a2d81b1fd194e9ed3960f2881d07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-attacher@sha256:1d5ad3ba6fe8edc2405bfa45a75cca411cdda308ad4a3437710b6bba8fdaeb4a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-attacher@sha256:eb7679dfa230f000f64a1863101d3dcf8a88432f23bcc2b8ff873808fcad2382
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-attacher@sha256:dc26c7daedab2ead0c996c1866e3be2d2e7238ee92230f7926f01ba45d71c237
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-attacher@sha256:ea20aa8429a06baaf6f86fb3a7cef2c1d58ad466841352fede3e4e0f6600710b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-attacher@sha256:731a3759b6e139596af394e8783a04ddf897851782d00a2fd7409124e36881dd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-attacher@sha256:82c4a5e559fad8151025e292bbb3ddb440e59dcc0c7f7995e6b4fd6ea38905c3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-attacher@sha256:4e7b8e5f3d53f31201e71d325ebce1adc920536902480e4b70ec11102a282481
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-attacher@sha256:b0db864e7744d38835bf7c43086856233f2a24bfffe8869c4f1b9ee84a688a6a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-attacher@sha256:ddf341484391cc97237dd4f79583c1c592697b6b966e820a0119cd6d7e782a62