Sign inSign up
CSI Attacher

dhi.io/csi-attacher

csi-attacher 4.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.13-debian-fips-dev, 4.13-debian13-fips-dev, 4.13-fips-dev, 4.13.0-debian-fips-dev, 4.13.0-debian13-fips-dev, 4.13.0-fips-dev

Index digest:

sha256:f475da7c50590a2adb999e0fa97b9a30a97c1fa8a9ecd4de90acbea8e27dbb0e

Manifest digest:

sha256:3bd39be0a483c40cd9a1a1eef77a14021dc3d8adfa443f77af47ba6223d4fc6b

Size

58.37 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-attacher:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-attacher:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-attacher@sha256:858050763b8523214b648b598c034a8b819d620276276633881f6539aceb88a2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-attacher@sha256:2c356529947f058283b93211e387f6372c98562b079fbb9eec17ff4d743ba271
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/csi-attacher@sha256:9c22afe9f1711edf56ffd5eeec9bc32ae7fa6687c8ef49354ebc6f95de170f41
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-attacher@sha256:e60ed64f0d55f689b06f96b7ca2536ad3aa57f6e40d23883a6ca83d28147807a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/csi-attacher@sha256:8cc95d69d0803a5236d62f7f84c0cf05c8cb8344e4629e03541b7515b1742747
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-attacher@sha256:7b00e61ba9fcb31de2d33d8bf7e2532e7589ed4d7c868759f7b72ac377ca0eec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-attacher@sha256:c5361d1431850f2b6c96d9289314bc182255ec81844558c25a92cf0639d2b204
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-attacher@sha256:251fef453c70cfc08f73534adea230ad23dcd302acb9b76853e8eefc6f328866
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-attacher@sha256:f3c212a8aef115cf40777be06924fa299138416b8cc0a6f6c46657107a85ee86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-attacher@sha256:c3d9f5ac2bbc61d53e9f922549d4dbfe3600f5255301023763dfcda6856b2fdb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-attacher@sha256:e2654c5049b73a66d8d32c8b4db2872bbe6c279241af5366b9edce341f17c599
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-attacher@sha256:e7b47260d1817368eadf31813e394272416035ec554db8e93c8426a8bcc9fada
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-attacher@sha256:9c93671aeef31611463c0e3bb26589e09d85c33f38b7226e461278a4872e0194
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-attacher@sha256:e3abf4bb2ac7e84a034f24aecb7fbf59e5fb2a778058e4fa8dd4c5a01fc07997
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-attacher@sha256:6a8297987a6b9865e427467a8b86070bf706c9a9f21f0d60768a25e7901e2504
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-attacher@sha256:1ce372df691277c89cfa9580e60e74b53657e90e5262c0f02f6a42fbd4caa0ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-attacher@sha256:dcfde76585bae127cba80edd319c0be8733ecdd67b8ffabf1bb10688017f34e7