Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev

Index digest:

sha256:35deb0082e7f3067cef9e02cf6efc6cae2b50cabe593d297bc6473c65679e360

Manifest digest:

sha256:cba8b209d1fcd89413a012f4e4fb3d0c1021c97be68945c3ca07bdce9b236efc

Size

59.16 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:1e3d27b9d501ef74ae37ac894181c489576ae9f798e7e2a29cbcb73d94512a63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:0ee1dea37699ca9a3df61ea791762f3d4f635814bf36d39ea388627a711f27ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:ee210740f520d4882ead338ffb0726af8dfb7c0d395bda4884b07f3030db9da7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:813a11b89b72db5158399fe6fe629582b2c58ef00e7909c47674536c1820c1cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:104e5197f2940af679afa693cb6fa586cce5e59af9485cc654ab05976d20d724
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:86345c9899b59d75d15af84d671da9306b4d687d10c1a5e017163f3d9ef6216a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:ae255f95db0ee9d7aa9de4a1b03b03f74c97f4172e1d20c48d2f80dc38de470c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:4eac482873441652a4389184098f092637612f01b3041259a0b7adeefa31b77b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:c2ec7abfc595dc70962a853d21ea43f773e1c2e0da954626da4123075aeed2ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:ca0367385d3baf559d02bcbe076ab86af40dea9deb0edf265fa3540f835512d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:9e091e408fbd0eb6f218193ebd601c19ef218cd152a90fb064aa1fe25b5ec69c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:e7dfcc3cc9687a5ab85919d204b8d44bad0c8e48934c4513e5be5e4739717768
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:7dccbb245387653d322bfe20f256b3d221bc88cebfbca30a467800ca6656bc58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:4c3ea72f3935c13c23f7be3da30b8ab47ab3e50258c2e904c9db313f8179eb25
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:9ee5162ca9844a3c7eda2b634c4441e8d350d4557795e4076727955599804143