dhi.io/cdi-operator
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev
sha256:fb4044ae7fb0a25b702b2badc982974a9505135a86ea4d487288db201794147d
Manifest digest:sha256:492b25044bee4b90072dbec91f4e88ac6fbe7ef202ce2221c72bafcf057b79a0
Size
59.94 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cdi-operator:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cdi-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cdi-operator@sha256:d92338ab426545f5b2a30386c032b31466fa1601c7c479c9777510de5a64fbd3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cdi-operator@sha256:e5f4339368af72454bcd592a464341b56036ad13a3eb620d071ec448ce5c4067 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cdi-operator@sha256:15daf3faba6e6e129a93aedb9be80a66954d5da3aff1cfa9f5399a3c73ba999a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cdi-operator@sha256:13052212a7b7205e422af8d86c83b46aa528ea806b8b05d61758cc11b26ad03d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cdi-operator@sha256:e2990c71fe9a3c0f09d3cf1bf41406a40f3fa3d00c3cba6517eaf55810247a25 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cdi-operator@sha256:ac329c018649215a469ac26b6dc40174853ccb9058cf6a56d0c351a6d94cb206 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cdi-operator@sha256:d2b6fc2dcab69f03a5b656d13c7c4050934b504bded1ec72ee8e0e273a1e7fd3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cdi-operator@sha256:654ea8389b4120eae81c358dd8fcaec001645fd594de2b814016eddfcc9cc1c9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cdi-operator@sha256:01dec6831566084c7c954c51a2e17e59178cd720257d70554e6ef380beb882d0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cdi-operator@sha256:b0ac10c99521d84f0a44e47a1ba207a721d86cb677f84c5d4753deee675dced6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cdi-operator@sha256:44fb799e69a3c0264dc0fdb12ddd0d815a5f5ae478ee85aa19d4ec0545cd38e0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cdi-operator@sha256:b5925da64fdaf3a34c3f0ab8466c9277c65c6fa3896a7d97663ccdec97604c0d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cdi-operator@sha256:2ce0ca4a1a546e6da826cd5d9bc60f939303a2eb4f09aa31cc18b2af8e36a8e3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cdi-operator@sha256:2570392c055a52eded36692a43ff4b39ec61679f6a6be2538f19726e37c5aea8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cdi-operator@sha256:642f678e09d338e0d1c2b82e7ea93999cf88a2e36bb2b30f2dcc859aaf7a1b12 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cdi-operator@sha256:7c687ec87c52be5f248ef87b423bab8555b36ee323dd0c09a4bcfbde517f6d85 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cdi-operator@sha256:020de8141a48e1a733ca5fc9fadbcadf0552c1bc46f1acc53548f888d6ae0104 |