Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:a86b7c7dc509134ffc09e5062bedd48859cbf8223e198f4178b8831fffd5496a

Manifest digest:

sha256:b458a9dca8350a69cac1548d5a8b26ed32caefe88c349f2d1ce2ea61465b38fc

Size

26.49 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:75c2d620cdbfc0f23cd4cf5288982538551ea4986513d60ed740c7ce55622e7e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:8e3c4b378d64506e822cd600c00f9ba5270b6a8d34cf4d81d6c4180023739526
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:911f68649931eac1963cb380693f5b1dc22ec7ad8326b9a0e1621316248f4f9c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:331d89a0710afe05b022109d9d72aa85593d0eae952a24ccf053c0616c44891d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:2e46ec989a80d108881ebe668d011303668aa4da1359e7a02656358974b715d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:91834ac37122e822ff3123f7e8501c42287ed25d60c9ed367da79565af0428d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:d802a1505171f1625016dd34a7170820db7392e41d0942529629d06f9a6419e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:a5bc66a675d1083603b001de0111e86cbd0f2e4f76f635652cbe9fcd9b7d2d87
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:e145b6ad21035349442f0a47b4a8dfdb14b6b217a27b75a5ede706c2d8b247aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:de565021d2d0cd49d99fc06eba1d97fe21ae6e1e5c376cbc93459e8d034cbbda
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:8805a00cc4aa889d42eba7b2fdcbbfbc12b2418ba3ed26e043acc45065250dd3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:da092fc644795500cf3ae4d0ff9d0a4027183555e791394cd7f1825c425653fd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:b286af99049ce4e97836b68089951c0f36249f708e85369162f953bafef26974
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:0499a55ca393a56bb9f4695628951b9898695e5f8b29207f7dcfc357a087a5a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:9a8ee37ea30d0e768a51a75370d9414d42a64220413b29f9ca41028d4b918651
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:be3d456b9bfb829b9893859b3d7bccb6429a88f2abd0bbc91adf1b20e6006563
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:70f970e3ab58bef52abcd6bca598713dee361b31db589d5b580d1199355299c1