Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:20d0b431aaa5c1e566ecda95ed6b15d79faca3ee030ecb70444f280a6e47c477

Manifest digest:

sha256:e063c14965fa5076f7cb152c542b2f8c6bf6b6bf7bfcd8450ffaf4a3a39f3ae3

Size

187.36 MB

Last pushed

8 hours ago

Vulnerabilities

3
13
2
3
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:39f7460033008fe85d7fb5626f74f8fa74c973c65425beacedb1407793f1dc98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:2ba12f760722fa4b0f4c404907e18a883d1722377bdb0b775cd20a0e7826ac40
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:997e0153b0549242020539fa11a8dd8d82f1f700ec7d7d8aea414833f8271d19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:767ece6d4305ef195f24316ed2558cb03f4cbd40e58c1970d4dc315898bf826f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:928d00c13d304db57cae1f82fafe13af6892773be2bccd34c91e8f4703cc51fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:3adb012a87937240e9b05394722b9945cc74f3a457e341960d6de5b0c9421498
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:4ac8469cca61c4c2e48601011067b4ea7d05a8f00d6cca7fec7cafd7c6a68a04
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:1802cc473135652c0ed32688fbedd2d35d07adee328017678d41f0793fc09d64
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:f692470b90f5fa1167ba74b1570c5def021f491b8a0819c32cad52ad4df913a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:d0247d0ea3b6081286902fd9b5b3d41a230bb9e735b3b43fd5496bae59771425
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:e62221f5986c2bcef56786d377d6f754e2d0633f14f0b4e0bdf04b70aab263a2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:691d1c4dd3846218ce63c2d5e583800a99a04e47566b40822812fb5ed2566bac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:5a5bd6cd568887d5dc0e89cc8edf63046c95619a4f78e2415ffa480b86426b54
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:51ff4153147ef0dda5f8c1f9c95d247d743570840ad845ed2803a9a218ffbd9a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:02165e9f1b5fe7d7017c4750c8ffcbe7ddac3e54c3f0151b145ba0d45863a6a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:2d10e119c4d1b6a55783ef44fd55eac09352a9ab700c0ecfe4fa1a7786a1eed1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:ecbb3c461261735a42ef9426358e5bc14c354cfbd57d2b9190adee2c437869e5