Sign inSign up
vSphere CSI Syncer

dhi.io/vsphere-csi-syncer

vSphere CSI Syncer 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips

Index digest:

sha256:336ec54ea41dfb950cad595fe4f13f6d100caef02fbe0703cdcf00bab3a51ca5

Manifest digest:

sha256:b21e7afca96514f2d76b763f7d2e6290d5456e459dd78dc36e70133bbeff3315

Size

24.85 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Ends Apr 2025

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/vsphere-csi-syncer:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/vsphere-csi-syncer:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/vsphere-csi-syncer@sha256:44adcd1304fed226642d14a8bebf0e8d0951555f86a2f38f9ae90017a43ebb0a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/vsphere-csi-syncer@sha256:95fe8e750e1e37a0f09ea0ae4a6413171cdf10973e15aae2730bbe42c2789971
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/vsphere-csi-syncer@sha256:adfbd1bb545e626d515e2d95c01102a66bb5cfdae2dfa8757afb5c263849211c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/vsphere-csi-syncer@sha256:93964f67aacc52c01c4e702cb75cc2aecc6c7ee0237daa160dd7a0750bb11f38
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/vsphere-csi-syncer@sha256:21f734e518f423b7b3281c31e8dcbcedf9152797fba733e7fd3e43bc391ae23f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/vsphere-csi-syncer@sha256:c46377cc2a055692d76d0bf2e4f2a1740af3ea6bcfff54994f8832b65218ea8a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/vsphere-csi-syncer@sha256:c8287efc5ea7d729ccd7eba0bdbc92c5d720d04015de98138e247d251aa12ac5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/vsphere-csi-syncer@sha256:87dbf0cb810deb725971f14d3cf4c78d55eb330510559402802a0d9784c03e91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/vsphere-csi-syncer@sha256:512a469acc057e1b60ea59f7bddd91796f6d9e7b47aa7278812b3be9e6acf41a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/vsphere-csi-syncer@sha256:553de0041aa4ec2a14e4f9aac2c7e440a3652cd1d31e58814ac2b2b3f62ef04b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/vsphere-csi-syncer@sha256:30afa9724e7fb4be0dfd2ef918a24a68be71a77779525af134242a2a8c7d208c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/vsphere-csi-syncer@sha256:a19438fa61da29ed706ca509e2cd58d0d976fcb414c7f74ed01061b586591ad0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/vsphere-csi-syncer@sha256:19950ea085edc1e8a36c856420160d26de84d1ae1343b6f2f9a0ff95e516e396
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/vsphere-csi-syncer@sha256:5c40b9d253d282bd297538994e0271f3d295e07374dd8bdfcc6955e67de77b0f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/vsphere-csi-syncer@sha256:aad2da23603f551d6d3952f536fdf0aca4c94aa820cf562f849403a68677623a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/vsphere-csi-syncer@sha256:f975d5471e550ef2ffd2aff30eff5e6eb019e0a666fa9bc62d14ac45465aa79c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/vsphere-csi-syncer@sha256:c5987be05b637d7e2c6586d01929c048d0f0fe504cc155f5755f7fd4e775d2f2