dhi.io/csi-snapshotter
8-debian-dev, 8-debian13-dev, 8-dev, 8.6-debian-dev, 8.6-debian13-dev, 8.6-dev, 8.6.0-debian-dev, 8.6.0-debian13-dev, 8.6.0-dev
sha256:7b5a2a0bcc91b6a863e507aaa877798388cfc33d1ec7ed17591978282a87e51a
Manifest digest:sha256:d494baa7ad9a41dfad6c88a1b62d84ff43154a6494a1768d41908d61db974305
Size
56.21 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/csi-snapshotter:8-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/csi-snapshotter:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/csi-snapshotter@sha256:91b997d53866cd38c7bae20420c9ddc116a6c44b4f8f274cda0fb801963515c5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/csi-snapshotter@sha256:06c4fb330f0e4ba495445690c53aca86f0efd07a19a98db6f2a164c308b20a06 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/csi-snapshotter@sha256:5e720219c5fbd06c8a28f0e969655134ad3c96463c43fcdd591a53c33f438fd7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/csi-snapshotter@sha256:3f9c8032e506a126fa4a01894b459f57b7af016b1a8d9d8bd3df45b0bc3acdf6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/csi-snapshotter@sha256:fceb425a7870d3df68e443f0b9042881a2c36ae2a212278b51edaad295ea9942 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/csi-snapshotter@sha256:df747c73359ff8309ee74522bf84e5b42c6eea82c6e50d86c9869db9df53ff67 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/csi-snapshotter@sha256:784c2672d87bef9d7ecf2090bda1b33d552b221937ba8f353f7e62b689f84b2b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/csi-snapshotter@sha256:4de6aaf73ed9c15782f13fd47f1ee229b56c6111bb81eb0745a026ac9a916d26 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/csi-snapshotter@sha256:169e330979a87ab200e574a1551198edb4ae679c401491528891359d786731e0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/csi-snapshotter@sha256:d1a57f773cdc3b46ef8d5c13a8d6430e8b36eab96e98ae4c3bccb438446d2d98 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/csi-snapshotter@sha256:e5d8f21601d06365ae868787700fa2c01fd6159605c5b5f4515ddf35ad709b62 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/csi-snapshotter@sha256:35be84912ba1a3a5c26b0f517b74c383fe36a99295195358853d56e38e5b22bd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/csi-snapshotter@sha256:68f082a3d7efa5b9ee6f6fb13cbcaefc9efb897fc0d3c27772ae72d7c133b5b7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/csi-snapshotter@sha256:ea90a9cb8d9e5d46ff5cdc3ffe1b08863d8a2e308d169fa424f9bca1345bf22b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/csi-snapshotter@sha256:f80179e101335ba2c13c2f983b59c00e8c724b3a2182fe0459967fbfd1a8328b |