Sign inSign up
CSI Snapshotter

dhi.io/csi-snapshotter

csi-snapshotter 8.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.6-debian-fips-dev, 8.6-debian13-fips-dev, 8.6-fips-dev, 8.6.0-debian-fips-dev, 8.6.0-debian13-fips-dev, 8.6.0-fips-dev

Index digest:

sha256:ebe4e5f69419f43b458d38d5fa88c265bcf046738c20c65192c0860b4039260b

Manifest digest:

sha256:87064904223bbbcc86d27b27485bc6fd7a6d7b4ac44e4985399b6d23b4f47b84

Size

56.96 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-snapshotter:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-snapshotter:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-snapshotter@sha256:81d2689fdf83b60c41d1e34ed9d513834292bcd9fa09c09b9256767ab1781923
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-snapshotter@sha256:0eecf0987464e85b96176541f6c493eabab25ca4efabe9588b534d854a12191e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/csi-snapshotter@sha256:fd04c531da7ae5ea5222ba6d7fa005e060a2ea08295ab98ce8fd1f225c67afd4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-snapshotter@sha256:fb682a1590d98c47a1b8fba915b5e3aafee263f393a89a9ca2eeb6b7e43b950b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/csi-snapshotter@sha256:1baa1ce5fa101a17c3f73d4b970805787a431dc8fbb67180257ba43321aac0c9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-snapshotter@sha256:bac1f48b1ce656b5710fe95792f5b4a89ff9e287d742d699d78ec22b8d3eef5a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-snapshotter@sha256:0fb1cf1c9457ad2149c895f62777d935fec59c2e5147bcbe4424694892cdc9ee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-snapshotter@sha256:2e53cf8135d86d29fb3649d30582a29ff2a584f08e30b12417693854744ba21b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-snapshotter@sha256:d087cf42fdeb21758f2666781e6bd21c27d34bdae1fb46bde9b11c45c3211052
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-snapshotter@sha256:58394638c4405543a08ba505c88ffb5091ab804adf4ef323cd6fa65b31b0902f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-snapshotter@sha256:6f7fbb8f5dd4b579272eeee3c3922a4c7ce6ff5b2ea2783d84a5f976e18f9e01
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-snapshotter@sha256:bf2c4e0ab192222b801a684f500f317fbf699ba829db279fec1b563edb16f90c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-snapshotter@sha256:b76c86a19e632b2ca544610691c21459cfe13d1612c23eebdd785333dc30aea1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-snapshotter@sha256:cadbe178be9781be24597ad8fc24c1d57541b9891f5da21f15e867effd13d1a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-snapshotter@sha256:020af87d0ea5780ef0236e15cdbb2c8b8d5059b337d39ac9d47922d088a5ae29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-snapshotter@sha256:257d86be1b2c18cb3a176f9b19f953380f38fbebc6199b04b28d1dc7900e6017
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-snapshotter@sha256:001bb809909de2b7614bb6ec07dcce6e4ffb5409740879bb86b50619999379e7