Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:e1973045072cc60b704f773a56468426193114b4a93b85128afa796dff228e75

Manifest digest:

sha256:cfc2dad95b47d4d122ab87d18723c325cddb530a167197b56d58541ebf8caa03

Size

59.96 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:00eff5b044b8cfef3e8c72b8dcaba0ee8198bf906ec964f13ebb2843b5cf1637
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:9acd99c04c2711befe800957775ad6cf9196a7600754f33ccb4b41f8461327f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:bf715ee6e26ecd3a143a41ce42c66fe8dceee3b3b2685f1f5621f73beb246965
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:dce5cd47e81c6bef2032e14e00aad1c893e0e1280bc6c9a7409443eaee7340d9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:5887fd0f4a617d194b1abc0a1d9ab619a10bc32a0dddf80c959a906331faa998
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:8ad8c32b315c45bb00ce5b5c268d648ed9421666f51f215d395e27daa2b9fde7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:1e3b1f43cb5388d25d54ffe280b05f4ba017eb0b3b83718709ce336a8deeede7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:483a981587d4ce169964ca3013f29c7bd4542c2a351bba7cffbd3ca6b8fbf9a4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:e1c74be9508fc0c0a08e325444af8c0daf0e86ace5d855e72893ec9d03a7d834
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:97d21bfd2a4ce80f2c5b68875f7250096def53f56991adbe2f3d13ff4da51cb6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:8ba2a4831ec17153d1212c7ebc7814bbface3331f62cbf775b07823baf6acd47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:6d837c7d76985607792d3abebcf89441c9168d1bb85f3653e2bd2760ba38d64e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:76e1faf4a0d3aa61614c459746e487fbb4cd5411dc6c90a59c71321a9a03f130
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:657fd9a9710b2f4b5d147d3b73ca5a920881d3b4044efaa45e70da1a7edca69d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:96649588c398afb9cec5ddf398b032b16fa0adb3fee4743019ead19b1bb7ff3e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:37553c6241572a7d2572ac02dbca9b5e4f225e3f3572f2610cd3ff908d894fb9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:55b991ee031bb6c2b514e6628e60bf3a634ba9172aaaf4751f7f27e58e329b8b