Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:3c08661b28f60899ce69653380d8949338c820a2e18d98888e38135aa2c770de

Manifest digest:

sha256:eec456da827f4f488efa5d2af51357ae2b7c4c9b91a93950e1aec766a3e9b516

Size

187.44 MB

Last pushed

13 hours ago

Vulnerabilities

2
4
1
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:d6c7188426606f2e6fadd6be968d743388b502038ee332688a0c25fcdedda517
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:f37d00d838ce54bd40abc636302fe8ad9f8ac6b637bf2f693ce2281491940406
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:a6ec4987190fe57a9816e63d4d4db97413f22e0d555062d7b0a2e99a84718293
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:b392aadba7e80e9e860c544f97ea2fed5625882dfef6a4f383864d4e664ded93
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:026845c0bee984b3090865cc6f303fbb5138eb5dbc662abfa50af918a69ea8bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:e63f5aaaf5639229dd9325c9c0bc9d9e1795df10d745e8e7d06cf5079f282369
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:9cb1eaf525ada2109aebe4f86f4b3f0beb3453a93715be6e8def64f272731933
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:fe4ef2d2c4eda2c8745068b999ae912a5b7e81c75c1ed5e449d114ec379cd77a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:49e3c89951448a7701a7bc57143027c3db86c5b55dc612731629466df5399b11
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:1f0dd47566bec34fe2e214466bc2582eb7640aa1417dec26a3e585d816ca2cd6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:69ce33544b076f33a58710ee6051f858667f224c15d7fbb39b0a298c42e0acbb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:dda3f62670fec4478693d2f633bed5e210797dc1130dbcc85716b34c23bba71f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:86488e75d37ceffe8e944752883c83d41e704cef4a871aefae6cd9afb9137e7c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:7c3c0eb0ce2abb2d2c1d230be2f80e2fa542ea84d481a4b250ec0678c59a74ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:3924dbbd3b01a4b33028d11c5f2c0da87b70f78963640c4c57667998149c6405
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:7b0fd33c4f16b4a47f8fd2e60d10595ac90056e9aaff124cbbc55ab8b086bb75
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:e48be8a55c42994cd673b09942c548891a0b68062d7bcc3b1ff763f7acd004a2