Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev

Index digest:

sha256:9a583e9d4d23596f9a14eb4dbf13677d379653e45ede30807f78ba0996e77994

Manifest digest:

sha256:e01e0566d6211780a1ea2467b5cd2bd48e1608a83c416f05e7d62ec5681a733d

Size

59.18 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:b6d6e7c609db9f0a159cc8063cf447ba8f18a9312562be3957aafb7e40b7597b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:82b81bddceec04720f260ecc1c706e1ae4c29b726f1935ab9791521519233947
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:78306b8f387128fa332cfa5c345b8487613de3d7c38d8f81fb63eebc3d0c17bc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:9f6104f843cebb1769f50fbc7d3a6b4c844c12e5fa7fb596661ae1d8fb43591a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:09b9c861ec12588eb3068f5686fda05c8e6cbfe749ed144c12edef9fcb82e8a6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:6bd9eb158a70e611c1aebba462058a363dc9f1f5da57296135c8e9b6db4c8ad0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:1bc16b64b491fa128aba29bb403e1311d31a80b544f0388fd7d32858e880660c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:62b7c59c78426b6654c13dbbc34bbbd2181806e695f20e784f5e5d7cb438dfd5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:d223e1f49baa60fe52111e6d9ac9714df6c3de943921ff813bb0d9fc44fc0098
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:9a64f573f027185e7c0087af3e0fae2c47fbc18f3899374c78d4bbad98b0ef02
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:35cedeeb97c6771d33734e6c3d13ff9e0fcb63dc30f55bbc2b3cb63d255facc0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:f848ebde0d5f1b612619ee5bbd860b934c68d7078d03ec78e53b6af4575291c3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:1a914f4be3aa07daa882e1c3f7af08561e82447156506beeea015a5c5b02a302
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:7295511fb8ac3c48e3217e4f5035586c0e5dc774ff98274ca75ea582f3019daa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:14190b5b9e185059ca48e20eaabe52ebb8027d683a9609e54ed360d4bb7895ee