Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13

Index digest:

sha256:5b161c8445a8a8730e3544c94a926a6e6e664767204698fa0c984326b8371202

Manifest digest:

sha256:857ea8ca1ff68e867b08b0fe2db59903f31e3200243c98eab636577162b6f48c

Size

18.32 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:ebd7bfb5ce47c0e8fcd7233c1afdaa5316403e920b2ef4a3f1292a626f99194d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:247effc428ab71cbe73102ffa6c92ff04493656e4bedf21d5bb9e9e5dc946ab5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:b1715f8c176376f7aad45a259b3c841763ac204316559b0b963b61803acb6bdc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:6f22932d5965709b91b2a5a217dedaa32f63e4d29bc629ef3e49db0f2ff1c94a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:a21cf04d43ee7868a4f1d0b5dd34534600fdbb598a3a182ec44c66210175dc44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:a2a475d1054ff8fbb389ccd86031e08527519fa5903e9b9b917daf8e65931d52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:d4c1dee76c286f498898afd2778595f121f5d4dc106e52c5e8e2686bf2645a50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:d0c08b8964fb25b24a7bc7c122365e2c05d1154cc14ffcaa646bbdf855e5b2c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:50b7b53faddbd46c720020fbea46b7c3863c32b09e6ba6880b0eb29b8554b4c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:83617d8526e204bf9aca6655c882f77a4c6a6a66706eaeab1cc9192d0bbccd63
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:a1220bf8850ac21c4c58b4d8b8ea94aa3ce146dbfb72f341112d485a8645773a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:35a5e95e0c8355ac732ca3517beb6cd7c514318727d2c79b9aafefcedbee0472
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:71b841b90af2b519b6450b78d8bc7c94de2b087de2cb0b54e364f342f55475b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:f055c1b93b4b0e9e7487fd634beb83b517549b5580dbe6e08f61657d026b8bed
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:d540a99ca9a85c6910d67145456967aa12a021984d0a66404877f107208ffb04