Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev

Index digest:

sha256:bb8cc2f617a53da962a3dfadf61fb903d1ef40a98585bdb51d8f25af3550bcf7

Manifest digest:

sha256:18de88ff7ce33c7660b7ac7e466c01fdf47303d82ea18c48e2cb4496f2d5915c

Size

186.64 MB

Last pushed

14 hours ago

Vulnerabilities

2
4
1
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:53b2a8459fa1d29b5df04e99142d8d0eeb562ca557e9589a23aa49202f647633
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:3c34bbecffc750877b3453640362d61912171b0e6e0cf21e00ecd078c8320a7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:b2931a9f411aa6fd573e3fa4377f4df8d4331c4087e02bac787fd1e4fb33e355
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:dedb5a21cbbc56d72ed23fcc38b0eb83173b45189f9a3507ad0437588970819d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:596032d08ca9bb24183773219929a32e5260161fc1a93ee7f307b05de094d266
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:a1e583c158c4c173279a09c26804e0c801c117f6338e5658a994c95c0773ad93
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:86cd6f816fcbc6b32e0682dcffa72710f885fcdf5875cd6e935e52e5631dfcb2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:e27c4622f6b24a327a912aedff2c0b488b578db7ab1f9f3f7bd29af18dfe31b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:9dea5d702ce04cc0d778041500f697a968b8200d752114bbc904ca5299ad1370
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:7b5ecbba7148212f1ec1131f13de7abf4b6cc951fcab6b42797492c778303c75
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:6e80bf844970c54efd89614fd57a8ebdb384eec7a4c5bf37c91c08614e5be0bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:5ea543a2fce4e26927589e5effb1ee7b8e1d33babe4342e8d610c6e4273be6c5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:7586be122f2e2ee3e6cd0f1d4b87450dfa03a455d501e3e253d2211b395df393
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:365e0d903f30da757cf9209771ee0f290e721a4fa42ac5bb01179575d0db9d56
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:4dffed60fb4b23ae62a721d79593e926314da1bfd8cb4e44b733f519572cc37f