Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:15c57341aa6ab4a1be38475f73946afaf79bab389022884f7db830a437c057f4

Manifest digest:

sha256:d4677b4aeb2f1696ba3ebc5614c4b78eb54960b2ce5724d91d8fde17cc5f8a75

Size

59.94 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:28c57eca32cbd31fb9eb934dd3962b166d80747e934e5e227e087374f1432dd8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:5cd93127702c25330fc3c737402a1232876fee458657d3c72ffe350ba385c9ec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:b026b02c1afba9d7fe11150f2eede1604ef38eabe61c0edfb0986b8860d2f547
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:3add6708b7f91a2022b5e5be56bff39e25736a35276b38d9c38c450b610825d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:faba0300af6799f9029f902334307e869f5197d043041cd28eb31f8e738ca334
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:03fb8b93b3df04e4af50348083700734f236dfc4d7bc56a7d0ddaa808df6d404
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:b6d7dee5967c719ac14650bc15f50f6ab14361acfe44dc056b6c6c50a28cda83
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:834e64acfb98fb6328b9138d71ba1b66a951c56dd047a66db9c37ba255fdfb6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:87717688a17737da624a6e9163a20642d4aa79dd348183c0ad2d8f5a69ad0733
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:5e44e81403ef296b2bf71a05a0ccaafd7b6cde08befaa8e1bf7133f8dc1821b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:818147d7ede45498ebf853304b6e5f06a41767c85a2c0fbca91e6e9c4606e564
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:e26a7d98a14f8950be521a1dbed6b0ba6c3217fe7a1f62fbbd70f3e5989349fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:2fc0682ff8d7ca2d57a12244a39f24b375390bbc310ef2e6e3e553e192c33cfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:afb4cfe75ea7ed9d136642e92d3be04cb57a4a42f8364dfa8186dab05041e7f7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:9f61cca0a613dda435d103085a6c937844d405de6dec0e5a2f794fc319c276ef
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:fb3829a99d9ea57028ba193a3e85a6df53e4076cd71d6194242ff57039773df4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:fb9ada12eb380d7e01287f8c858a84c2ea4617566d435b6470c285e684f16db4