Sign inSign up
Calico Node

dhi.io/calico-node

Calico Node 3.31.x

CIS
linux/amd64
debian 13
Tags:

3.31, 3.31-debian, 3.31-debian13, 3.31.7, 3.31.7-debian, 3.31.7-debian13, v3.31.7

Index digest:

sha256:6e90ce929c049ae2a5ca79b6088dc3b20cfef754e41e09d9b4d42303b6b4c7fe

Manifest digest:

sha256:f1841a442707f4b639bfa6dce2a22059c507ff64a7b7bd1b5df97570301c006c

Size

56.08 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/calico-node:3.31

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/calico-node:3.31 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/calico-node@sha256:6cbb97da777dfcbd46014468f5ee1fe46918e0ef9b290c45472b5032e6fd2e28
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/calico-node@sha256:e5b85ec8a586be68f2dc5813c18b339bf92f704d97ae30b81402a706a1315282
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/calico-node@sha256:004d856c6888d1748ada34451ec3f62c3159d5af5b9e5d5b8c1b4de27a8702d2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/calico-node@sha256:176cf86cbf1b9073b6aaf1b202c954022f4b2bbb96502b78524fb73ee6ff71d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/calico-node@sha256:ec2663193a2ac744f1876bbce880dda3f345c780248d226d2209a4d39d3da08a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/calico-node@sha256:1fc862eef3bded9fa218e412b95f6bdd241cf064114dcfdeb358d2b17f8066da
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/calico-node@sha256:4a7e783e09f8ec84b4dafdf2542c712a7d8fb962324038309333accacb0f45cf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/calico-node@sha256:b433c9fcc6ad8212fd0f7df54b3c719260114d763968af6a5346e183d9cc5e5b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/calico-node@sha256:698e8530ad963093332a820e47f01c815705f52051d3e310e1da7a74a9a8217e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/calico-node@sha256:b4348f0c967961b8a937375876d6e09909e83d9aef84dc76710befd714366443
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/calico-node@sha256:c286e8cf01413d5510a930250b6f2a7a457b70e122dbc2091f3e42e472a1d796
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/calico-node@sha256:b006be9ce577ce6d646e2379ad555f04bfdc8b48eac2f8150f6f58cfda0184f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/calico-node@sha256:4fb1980144871bc80ed44482ff01c44d55933f0eedfbd39b423dc2d5abbd12c6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/calico-node@sha256:39c95392f98b2be5e61c759fc37e3356c0a2b4c0fe3f3f8cea4f9976ea66f54f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/calico-node@sha256:cbfa62463efa169dc9a18c75bf1e2e0d24068a00f2ebb1eae3574a4f3ffce712