Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:71b64063a2e26c834618982a1982e5894ce815f738592d536a9551d135c2ec4e

Manifest digest:

sha256:a1c330c8ab9f2a3d20c02f7f9f96c43aaa79040cf9650095c7691038a7a71dfb

Size

26.49 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:e7a4925de5cc02eb4e1774171b7ff320f22ddd1cf5f5581d5d80fbdb44f7de64
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:0cb8190be0e15ea5fa614ab6fd539845860ea9156b7583790a1febffe3de5f68
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:3c83b44f6e61e590b6cbf370804152cd5695fd681c11e93e92095699d2d84715
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:f76eb7d429a8ddaf4e81d1b774ab54a38af88d6e4efe5151c45cbdd69e9ec27f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:c11e66ef856b63566b49d2f21c94e47f28cbfd368361e2e3d65af88b74a89515
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:2fb98c5569c84a1a19225f1e307937b558666437f21f444cfd3e8495438296b4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:698d50ec6f8bdc0870ddc96f2975d91ddcefec37cdadd3352bc62cf245201d69
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:2fffb7f5b41e0600661539e4c7e9cd085bfd983a792a76744fd1770cca34622b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:8c51c97b578bafd304ea50ca427d270467f84f159ab559456cb400b2c861077d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:7471214e83ffe5f3becc5583bf4fb71d7687779d603dff84980f00ad20b1ec70
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:6a894d844f0461c354f08792c995476b81b63fd5956fbd3816c85ed4286e1ca7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:798a27ae8b45cdbecdcdaecd7cc0a1afbc12bc6bfc549c5285cffe6fd8719981
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:a5cf61ed3a366fbf922232e2fa390be49742954083d59fb5d08eea514feba7a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:e7d307a03035ee4805bd0a101e83c5e88d013b28def851a32ed5e6fd1f566ee4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:ed3983eabac7e7d34dd5c7e515f979a4539d8818f5fb7f2c19894ba4a34bdf11
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:abdecedb8bddccfb128e2b9919a190ca279cc878fb174ece117633f095dc1b8d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:2781c916bf297e8ae169a2bee0e2953e875c8fb11cb7f7478296139e26562577