Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:081b65cd3e627dca8fc84597eecd79b067e7139c3306cba7cb8bab168789f1ce

Manifest digest:

sha256:18e27e150bf6bf58cf3104fbdc0124c3b0bf9f47f15f2beeb9f0d308951d3f86

Size

187.36 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:7e5a152fba1df5e3a64c29bc3dbed94187637970717e519e3ea77369bb0d909e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:66b517d53021465e12d26ae29a003267c4692ba7fdaf1c3ffed97a04d43c4f64
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:6b0f9663d29599537d8547b304d9c66dbec489809ace1c1f54a050588bf0eebe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:da929abbc932a80b5d3ac3d0a86e0368350637b196831166f5ba7ebd41e64c9f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:3e986a8ffe34cb355c51d6f56450401d0890bd67a04bc0be48e5525a23ad7722
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:49ab6d922bf9e8fa615c2505162e0ea18dbb220143ec8174dd1cc04a00d88aea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:46d650cdde6d3a222a9685abb22d4e8e8f970279e346463a343b09ebb2c41151
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:8af597878663ff80b05905deec8c8ee6b5c3497b16774ea302b17437fa3fe148
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:4509b65febe396fb679c83af3b80d7a3b3d2ef38054fc83e994d25db8676c491
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:30575c650c057eaf832d7b4436d623d37c3e95bf9b5d3e08580fb024fc69db87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:196221aee4aaa7becfb3cf9e8e24f793e066320d6cd7810404712391c18d2b9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:fed2be9f86ce75cf4870e9998bbfb7c61b1811c571e2b266a3a7bd11fc7e7f00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:a144691bd607ec83a546f0662fb5b6b6cd1a9c318d1438048b09307318ec5fca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:172e6972a33d424ecacf0101f56ed0a3734424b61e8603efd17115fcb2bad7d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:59a66f5f8fa7a662f66ed901fe8bd43d263c193258fa9b82733f6e64cdc5b379
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:995630ec80c0796cb519171f1f58c0b91cf6e3f6e87365e4eec33ae0c0f2f44d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:0319240dd0de074a0ca69a8b85318055ba21f336bff96f6a90e91b7dcf538545