Sign inSign up
CDI Cloner

dhi.io/cdi-cloner

CDI Cloner 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:1a1a2f875478c8964e818802d60c22541f0c28912bfb6bfd617a1b0db19338f1

Manifest digest:

sha256:bdb9b2bf88cb3ecd9a8be623da6458bf0b1ef3beced576a2da089333015648d8

Size

35.90 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-cloner:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-cloner:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-cloner@sha256:88d5c580bdbbc8bea2bb76ff051d7c0d2a98f0857cfe5263a86938252ff0955d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-cloner@sha256:8518db7c0ef1580957e76d0e8deef8ab587fcc6ba8d417da81a7643e59bfe465
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-cloner@sha256:30b45e34365d0f322bfe2f19808fd083306440b2de3efce1d1cc5cc54f06075d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-cloner@sha256:34e94e7981cc1874d5e03b89f3585da73f11764b96db9aa24dfcc2849c7995ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-cloner@sha256:d7e19891641b5383745a0d496f0f29b78d3637c094a561adec57bc5422089aed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-cloner@sha256:c6224682f23ca182f563dae751ff10a85670a378a22b4888ea634c9b985f50d6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-cloner@sha256:889a92b96ba6308e5debadbd16585ea332fa518811c3767757892ba244fdd36d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-cloner@sha256:181aa7f6752fee43e27c940691601053e7fbac2dbab46b6347cefca74693f3ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-cloner@sha256:da40403f09d52cb00ab3f4f012dc9a83e8e996a064bce70dcfda7d7e88e6141a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-cloner@sha256:4da402950858ad4ac02d2b21a5c0028a688db054e6604a01fe956c2abca46e64
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-cloner@sha256:9a424dcd36341c3ae96c0b91780733a85148f3731759fcd871f18237170ad909
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-cloner@sha256:9f65ffaecc43b94a60e434c23a60be0aaac5fef57a20517f2e8ee6df42ff1400
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-cloner@sha256:7c5ca1065164f70df2212bf80a00316059b878cb2483390b856e86d912434c1d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-cloner@sha256:61aa8a83d22c095df16ade87e7310c341690d78e786945bc3b4f3e36b61d1603
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-cloner@sha256:7bd625263da946e44cde588e5b0a81a755658dddea39140b070afdbdabedada5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-cloner@sha256:a32757334743c1f94763fe4cd8f20a675366274623d17915649063bc85de07fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-cloner@sha256:ef57c4ae9d5733170d353fb17693e5a1259007f07325205c7aa339165146411d