Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:21fb03157c8e11680015d14d42d86fa73b8cbd36de60ee188f7431f110ff16c3

Manifest digest:

sha256:558f1988a460cdf624f343782a94b1ddb1adfda014d0a18568764730edc84853

Size

54.49 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:eba98e6683bac103bd7ba5501d04683e50ac5be78612ba56a15d91933a089006
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:f2487154915b23156f77a927a0fd90b8b722db8ab36596638a56ac1bf573b10a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-controller@sha256:5c61532bd1be23ada8ea2966f2667ec6faa1cc7abcccb36c8c381e6d59feb63d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:dd942e2a69dda8d8bf06cf3aec8fbd54e8d65b2df635025362e2e4fb3e2d8db5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-controller@sha256:def771a6432fce282fb0fef03629dad9b9b4ea1c4dddad55f1fec93e7a9025e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:a58f36f989335e0cf35326583ee36cec6b2754da397a0a0be25b931285737a7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:251e97a7f11f7f5639ad60e9facba68fab5a458954208699b2e63e338eb0790d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:c92b87632061126bb013e9b9b163a6a701ff7236c5e3be4aa77164faefc89d1b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:91efaa3f46e9698541ee854e6338591c60a258602a96b9258e1b5be6c4468f4a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:847fbdcdda4d710dbba8b93dda6eef27a5ba4f55018df84e6d324074cd41ce01
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:bdf6be57fb4ecde47fccf423a7e00f5c989d252db1f2f724d3daab6f628fccda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:abf18e3845341c41d985fd3575b4618c31ff5be80c17426bee27fdafe68ef27b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:3dfe219f040488bb05cbf1391f13d775690aebbce18a19c5e5d5e74a6399a56c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:f7b1dbc8995cbb04397a5295b4342c30577962d6f6582d66701d6be8a8f18dff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:a70eca008de6e4c7f4671be841d53070d8879a9972de79a2d613808e38cdb39c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:c2d9cc05f86b6c72f062be7b3d9febd5eaadde6ad7f1933895c9b07c5c5e1a12
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:74d7c1f6e76339c97e9fd645fe5c3ade2b960bcd8eba1c0bef4802192057da00