Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:532f89488b7bfe37f03f277cf552856cd52f51cd29161cdbd2cfe3dcec3be017

Manifest digest:

sha256:865e6d088eeaa4a80992c7cfcb451583d752347e8be0946dca5cad6db532a9a8

Size

26.49 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:5eb57f5eae6111d76d8ae54d2a85468b16f67b8b6ccb9992613a9c0b49f50744
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:c351d26155aa4406aae88abd7ab2399216c9305bc8ac331da63460af7684be64
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:2146cd372351a7d90f9f698e9549fd4c2c41ac0a529fdb0aee6b914f8215001d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:ec1e96a4d5bd5b344121ff6847c1fb0780cec85507e17d9ea2692aff89d160fd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:f0d541066e03352bebf37b98c0e87684f72e97f4c63f4be366b082c59a739e59
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:835fff37a7181558b311606ec56e285180df42ac80adf2c765f77866211636d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:ce6a6be684d8bbbd8d9b8700aa7c5cdf6053aa81e7b665caf4808ddb17579576
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:7a5b1faf94a8b0b3b49d5db6894d26a0eee7e34441bacf78de50cae5dfb49925
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:46872c436f6c772b0f5500e1ba83e1085086e1d7866d9e69a070b0ac06567cc8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:26e63ce39e19792fb2b6b06c4a9f0e6cb13cb562bef37bc6284561c557da90ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:b286e35a2f5f3dfa3e49c4372d07b828492e8a1d8cc5eb796922b0ac16b6e249
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:165954bc4e67bb373a7411551553c803e5633d67797276bf3cdda4856bc937e8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:a7cc838f5bacbd5ca202f505982b3dfefa91959db5c7a355178a4df86f270ffa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:9902eea0d1fae01f5f56a50af0f3ace46d3bc4361f4764b039d1418942f63e33
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:ee47cae2ee5223620d37dfa203ba430ee1ae94ab4820a58171c96ca02c9a6a13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:53112585a8ae1a3ba7780672c0a14b9161f1ada3f5575f1d6a44188ca1d34742
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:8e6bb5655565745f798b53ae078a9ba578b804369f0d9fd5ec796004e5f57af5