Sign inSign up
CDI Cloner

dhi.io/cdi-cloner

CDI Cloner 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:22020e0f043a10e0b525b0c5ed65a9f28e01226e64dd1586d6fc674130b5dbef

Manifest digest:

sha256:9c04d0f4cc21c45b75a42c8f5a0bb91aa7ab5c59695c2b5bd841f171649deb40

Size

35.90 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-cloner:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-cloner:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-cloner@sha256:4236553af9ec43dd75b81a8dd8a4671faefe97fcdf26f062504b9e59886320f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-cloner@sha256:d2d13bf918c3c11a1193b218a0e57be6ee35c8be942d52859cf78118121105d1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-cloner@sha256:4d98926a4cd6341a5eb8c7a9796ab57b0b1f9e27a3ec056988ecd2baf077ece2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-cloner@sha256:63b1a5b36716e839f9ab6ef481f3d58bd0eaf8894d9946794b74b27fb5321998
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-cloner@sha256:b0ac95de8756442c2c98c13f179f442b6e1e9c577d9efaf55ab036a66d383ee5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-cloner@sha256:3216947b15275d83f5d96bdeb93272e25a13357aff1fc64eceb34ed30b43c43f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-cloner@sha256:b9730100792d3178dc066013d8bb341ffca0a4266c6a4203eed81e8d3fa5508d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-cloner@sha256:931d069408111f562c26109018d71aa98164475cf3691486770995107e6776f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-cloner@sha256:32a2c426064e4157c87516a707c300aee07b1df2880a568ab078a18e9acc8e9b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-cloner@sha256:9baab71674f59c715343f40963b42912b9fb5c45a81c274f716d6081e6d5c7bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-cloner@sha256:aa552f437f53c8d2f26f0617efc165c49d997836e075d048450e0b100b7df854
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-cloner@sha256:57e3953cb900a92e7bf9e701ac1a5121e701628ec6b641a14150d694b61ec982
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-cloner@sha256:b143fa2f3460f13b10defa2242568fa4efce9915f75bc70ba9a18eef8487a7e3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-cloner@sha256:aa0837f2e05507958d085f52017d301d01f6cbe44dc3d62bf72ae879f8a36ded
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-cloner@sha256:e805bbfab432ecf02fb275197264333887b47c34546b26e52afb9915219d827d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-cloner@sha256:525f4de8be246c3f4f911fbe48fcc7475a164a5042dc0b2982d20bbba47b5941
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-cloner@sha256:2582d70ddbc5dbd0d71ac3007550a0cce0c80096460fd75425cce94bce97807f