Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:faae7cbbcfeb883e5f0fcde824f3680fb8174b6c55696423cdc2dd0e8e060d17

Manifest digest:

sha256:e501c9f33fd33b3cb7d33d03962a3b083d15d849e679f067d3ee4c1eafd9b546

Size

26.91 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:daed579de0375ca77ad3db3c0260d244c99f65edf7cfbf344b7c22cc8a032b9b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:f37187a0460fd1db9d40fa18bd8f42bb99717b12ceee5366805a9ed85dd36a19
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-controller@sha256:db397dd37025705760d6217ee4b189168d6922e6f97e38ed6fd04d08560f1086
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:25c7fbd40bbc4c6ecf54431894367f8e349c77b001d85c7e2f32fcd618d56961
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-controller@sha256:281d0a1a5939acc56a3a6ba26799e10343450dbde85f72670d01768bf762da6d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:d395328015b839629f13926f15868f18e06002fc0cb866e6da397f149b366dcf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:bbc7860bdf40293e9196e6eac79cf96b013c3882f87edbec10f81ccdfc39e0ae
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:6ec40b5a5f08eda74ab8904f85c2eb749687115cd4c5d9851aad4ea867554e10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:c8ced5835c0675df82a65510a236925aada45ca9bbefa105a1158518ab8a6c7a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:7deff2ecab4fa64691bcbd5a525d460e904bc9774628e13dcd28978390fa7681
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:976d4588ef29ba91f9c0a12b4ec668b261d819fe7a1b480c01ea380ca3fd2974
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:674e0b1a43979dda1aaf6567cd33ea4abf90ed1d9d1a5f8b59a3e0a7b2bc6212
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:b1a5768e8de3fc1d3e5efb57736b4b918392c3ba8b691c78411c1e608fd88d0a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:f19ad1d224959d3ce70f39e8365a2dfce0f94e3bf068f97f02e8fc114fab690c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:6b303721ba618a8c0f340b4d250e86082a21e627c4e869750158e915ef414ccf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:1cb712fb996b457ea109cae02c4ba71f070bc15bfb5ee85613241c44388b5e36
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:6efc0ac2b719e09286a2d00c5195fc496a13af06c347b1d459670a3d34a370e3