Sign inSign up
CSI Snapshotter

dhi.io/csi-snapshotter

csi-snapshotter 8.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.6-debian-fips-dev, 8.6-debian13-fips-dev, 8.6-fips-dev, 8.6.0-debian-fips-dev, 8.6.0-debian13-fips-dev, 8.6.0-fips-dev

Index digest:

sha256:5664deac7297179b6917810676305d265c6778925e2ce692cf40d2bb2c5cf559

Manifest digest:

sha256:aa8fbc39b6dcc033f9581afac07639c305a3102867b658497e86ae9cb2dcfe55

Size

56.95 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/csi-snapshotter:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/csi-snapshotter:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/csi-snapshotter@sha256:65ab3d5fb6305864f783cfed037e235b154b013bda08266a9655bb912803d8dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/csi-snapshotter@sha256:fc639193773a59359be0af1a14c9c86506434c7858542ddc0bce88c86f7aa36a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/csi-snapshotter@sha256:9d8c4315e0b73c6cda1679a7a71a8aeb52b5f533e41c68bc07fce4e88bf25459
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/csi-snapshotter@sha256:4023a967934321c9b5ce9d24d58e422f096400154c2d84d885329ed1ce0abdd3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/csi-snapshotter@sha256:5d7bd67d9a98fd0b7c442c84db0768c7e0d35f3c29a241df52bd226ed7d5b270
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/csi-snapshotter@sha256:b7fb6aba146133f322f42ade57411a40cf47d7441b8e22d5e07475b54bafcda9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/csi-snapshotter@sha256:78e05b425d551af45390bab96c9345346483a5f0967cf5c3318889daf54b7d10
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/csi-snapshotter@sha256:23658673ef4eed0342355ac9c3573ee2bb6b63b5f0165328565f6ef03a1b052d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/csi-snapshotter@sha256:38460774729f5ed49e7653bf4c77c6ca257f77f16a2bca1798a710770fb3dc64
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/csi-snapshotter@sha256:e4600b406024aad31759290c7c73d95fdbff6beeb04a70af6d361e596142cdef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/csi-snapshotter@sha256:f38a8d97847525d41a6d31ff830deb2f2266e22021e0da45a2b8f9c106c13cde
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/csi-snapshotter@sha256:fc1cf9ce9ab47ba581a89e2666266ea4bef9f41892bd2d21a63b27c84922076f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/csi-snapshotter@sha256:b067409dfa751a28119982456b3729ce7c0ed4ab755577bee6bb7ad39ceec31a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/csi-snapshotter@sha256:5b6ae0804bb9a3b0437f45f32a5f7f35b627bf05d760edac54b225d2ed426a0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/csi-snapshotter@sha256:0d01a49c281dbdf24b39054338aab8f4c9a38de0c24fae11db6c44d8cf227a89
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/csi-snapshotter@sha256:abb924f60f94afbef7dc331d5af4d88d6e84f09cf5e5dd47392f1c55486de337
SPDX SBOMhttps://spdx.dev/Documentdhi.io/csi-snapshotter@sha256:7fea9c41ba28624c63e593874cb257a5b3a95d1d19d45d53e499152dda9c6fcc