Sign inSign up
Calico Goldmane

dhi.io/calico-goldmane

Calico Goldmane 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.32-debian-dev, 3.32-debian13-dev, 3.32-dev, 3.32.2-debian-dev, 3.32.2-debian13-dev, 3.32.2-dev

Index digest:

sha256:d0245cb3e84a966d05eb084c822501d05354045e406bb2a9e252ace3348c6c71

Manifest digest:

sha256:be8c29439e974dd18ffca5576d485c07750b3ca524121c112d0e8838fa144fce

Size

69.99 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-goldmane:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-goldmane:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-goldmane@sha256:2e96bd4efa58b05501dad41fb1d0a6b7a4766fb71906bfeb5f6a55a205aa32c4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-goldmane@sha256:045e4359b8cfe537a61dcf0352edefe89cca619a55a7b3fb5af628c805ff08bc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-goldmane@sha256:bfe35de018a04bb80a260c523835b77bcca64a4c7b9e9b2d991f6f78f8929857
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-goldmane@sha256:fc27cb5ee6102b5ae5d398cb751cca789f085990bd93f63a9f2ab9a768caa553
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-goldmane@sha256:fe0ea9d085b9b27d9384aacc9be92a61a16d0a33924295c407910b0576a31264
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-goldmane@sha256:91e7976e1d348569bd0bd42e9b0570241b996245fad0476b2a9844001440b345
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-goldmane@sha256:bd57c3d895a36b6c6d7e610873f792c94fb4ea6738c7e1e1aa7e1b24f96be747
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-goldmane@sha256:8bfa7eb40bbc05083c04811db3759c081da3f7bf95277e21a7e1dee255ef5886
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-goldmane@sha256:3c26231eb933985d1ace501f18a2433bbd92335632c96952933b371ba4a2692d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-goldmane@sha256:ef0612a1791be8f231cd18af9f1b010cc5e6fe492790c4ffd9f493739ed48bd1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-goldmane@sha256:f3351b255bfb0dcd9e64833304336dc40e68b22d368e222bab243877195050be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-goldmane@sha256:3d25b14ebba2113f24058b9a1a28d0f81b219ec6defe495a9d02287ecd79a885
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-goldmane@sha256:6a7c81c252a1ae6d81a0b662f6d0851666524156bbefda925d841b685e04ebff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-goldmane@sha256:7cf53258cc392a33967d34049b842c96e68270f94cb2783fc0cbf8ea3fdf2160
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-goldmane@sha256:3623f76a6afb36ce303eb3af9aef6beaaf0f44ac6b3302861c63aef0a1c7faf8