Sign inSign up
CSI Attacher

dhi.io/csi-attacher

csi-attacher 4.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.13-debian-fips, 4.13-debian13-fips, 4.13-fips, 4.13.0-debian-fips, 4.13.0-debian13-fips, 4.13.0-fips

Index digest:

sha256:ef31e0fbe6ed40ee89df6db60c11880f4f4dd6a8b94c8ff513c5aee2fa487f5d

Manifest digest:

sha256:0f434bd14f6ce9da64d5f1dec271e55d2b14dc0d633e577ab443cc3e0f30e337

Size

25.41 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-attacher:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-attacher:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-attacher@sha256:2fa75c692e9daa223c643544e5588bea24624add42c873f129cdbcd39ed3b640
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-attacher@sha256:6a74c5b75f8b4a296f25e661c68a9529e7175ff35020d8076dc3740f6c2fa2a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/csi-attacher@sha256:fd836b569ff5ada6f22fe06090f29794ec0ef1114a124fffb85e73b0646cc381
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-attacher@sha256:50465891ccaf0d79b6990db279d5608699e463d0ade594633305ab08e596edf6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/csi-attacher@sha256:8c0e03e73b33524f2d71ce87773a067771ca6d0ce868b811e56bd947bea05629
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-attacher@sha256:cd9ba2276d663a4ed03142dd8aaa9703a336cbe6b1d9da274f367e038e7e797e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-attacher@sha256:d5d969d08bd5bc324aa8a88174b8fffe39f95d72fdf8acd4c1af2b8c46efdd33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-attacher@sha256:d3941e338328d14754e41062e5b2c84671ff80667486ef5a8d255a4f27322848
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-attacher@sha256:8cee57ad85c54916706fe699cd94e0bec06d3049ec9b843dc54ebd3b4b484be1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-attacher@sha256:a24fb047dcfb6620db5d300221c01a057db50729ff6e30c7bd519edda8f793b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-attacher@sha256:0530b7d4b643936cba9c2d8aef941b1e6e5e6f6b56753e1326a6a8cfb55fadf9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-attacher@sha256:056f0ea14eefa2d420c6903aafca8db79edca22a31cf034cfac1b88722ae9f47
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-attacher@sha256:bb2be35b2173d149c26b747d6eb375b961e8451d8eca25559ac2ea0fdfe74596
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-attacher@sha256:0c92400600d9c62150f407d2a883e17b56379ead823cbb1633dc0afbb11eea39
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-attacher@sha256:c753b87b968f94d1ece38e359c86b7806ffa3473b4b365f7b3aae6e4cdc40655
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-attacher@sha256:f3322b97b105b5f8f028656807ed78b2904bd82a2745c3a576592134f9c1fea8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-attacher@sha256:cb77d7adfbc94fc7db7746d7b3f7bf6ec1904bd790a20ed26278079620fcb969