Sign inSign up
CSI Snapshotter

dhi.io/csi-snapshotter

csi-snapshotter 8.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.6-debian-fips-dev, 8.6-debian13-fips-dev, 8.6-fips-dev, 8.6.0-debian-fips-dev, 8.6.0-debian13-fips-dev, 8.6.0-fips-dev

Index digest:

sha256:0357a8f8ecf5189e4aab520d634a7aa8d1c3d7dc47143a74c2255e4004afe5b2

Manifest digest:

sha256:14c55748ed1a72ff5c981a8fad86698e96b59d3eca34209841d39b78c812fa2b

Size

56.97 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-snapshotter:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-snapshotter:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-snapshotter@sha256:c1f44018453a57fcf90f82843290852247fa782a78ac534b9f96561a6e970d16
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-snapshotter@sha256:19b059ed92221951baae04364e378eec9c93246afadba274b744b3ca51c52e79
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/csi-snapshotter@sha256:4785fa360a3de4577924ecadeb35d2c611bdf312263d84c9864cb353eb16a25d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-snapshotter@sha256:03ddaec9cc36089e80b747788d0cd72a7dfd1a86c7150b36b742edaad24c95ba
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/csi-snapshotter@sha256:817547b73a0d81435bb458288f6fcc9bd9b9612daa16255395e15a98b644072e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-snapshotter@sha256:568626a2bde87d8d761afd5af233f70f31dcf4dfbea43c507e3a0ebbda71befe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-snapshotter@sha256:e0f9e588576d2a5f203751f26e3884204545636b1e6d8e0485369f44ca3ff42f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-snapshotter@sha256:defe00f0a0232243c4c9947c1e52af4f7f4f4f11bb1fa1c1ad11c5effd9aca5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-snapshotter@sha256:4d4f03db1b3649b3931887c9bd3fa47f48c8509c3ab21892a7b6424f2c6a183e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-snapshotter@sha256:d3328a67cb4cd58fe2f17d9380ebede0dbf1f6e9f6f24bd8fc21777f5023b70b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-snapshotter@sha256:38ac47b6dbda1deba48f42c2d84c4653b179c6a7680191b6befc212b3dd1f29a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-snapshotter@sha256:dc6e71d88c7cd3012c5f0aed3ba9a45107991e904aaa4c2077b8e7768eadd5fb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-snapshotter@sha256:0e1573e9d0403de368b9b4aea72dce501a657f5bdd8da731a8038a556da2dbcd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-snapshotter@sha256:92335cf6ec7869d8e2cb327208bfc8a1aca7cddb1ba18929a83777912f02e1ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-snapshotter@sha256:9aa969fc58abdd98c9556b28d5d96b0f21075b4c3b0a53f772cef841d0455cb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-snapshotter@sha256:a9befb97972589a7c7f77943901207b709f3e942f35dec8d7d6c4ed189c13fe2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-snapshotter@sha256:670043b11602464a8046220d4d9c3bbf6d34185f6fe31e062534cc897b5f6636