dhi.io/cdi-apiserver
1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev
sha256:19cdd304bd310f56f0be89f4c45d1edc0693e5d4eb6a50e630793ee7db4eab14
Manifest digest:sha256:da4cbb2bf05408010b88f951b67d1c8b065fbd02629768a68a4aa960636671b3
Size
49.50 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cdi-apiserver:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cdi-apiserver:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cdi-apiserver@sha256:f46244c1c863f5fbabab44e899aa243d7b2198bc7b1eee78486e76471abe85e9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cdi-apiserver@sha256:96aa33be1155ce8441f89d027d0a0547d0b3d447508f74b5044420abfae37ee5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cdi-apiserver@sha256:feb31ae00c3539977e1f93bf1fa982e0a5463163e67999da481f7288751824f6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cdi-apiserver@sha256:bc1ecee2106a8334258e5b8d42eb50f1c298fc958ae5c849129dbf50b621a447 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cdi-apiserver@sha256:700526190212d1cf4af84d938a1c7d7bf1fbf8120718665f6746863944f7c71b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cdi-apiserver@sha256:124af8061b669c0a97337ca7f1a6449375e6c1a7b74cb23dcc96d8fb8446b75c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cdi-apiserver@sha256:02286060f721b9f6cc8a5c844f8d5ccf0e923868aab71eb08aa54b176fd9b4e8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cdi-apiserver@sha256:77cca99a03d1d060686985d9788bb0f9d4d38791203d97a8ae47570e1da83655 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cdi-apiserver@sha256:4427324f87955d07493054aa3574439e88ab79af6cc02a1228ba2dc68b8c41aa |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cdi-apiserver@sha256:55bb9f1dbb46515852e3a9a3dac56a9e2467bf2186d8bd2a67d2a122bfc7b4f6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cdi-apiserver@sha256:be7836068288044b70da153fd37a6a61d79ca13e050b2f958c5a54107a735dc9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cdi-apiserver@sha256:4d63c80667263ab09856f39f56056529af1eca35b87065ee76ba843e5cf9fe6b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cdi-apiserver@sha256:7c5726d328e71148a3e38d509328303c760b7bbe27acd9cdb4dd199b5547e6b7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cdi-apiserver@sha256:2dc0475dc75ca17bdc305bdeea038f712bfbf11c1b1a5887d0bed558d9c1cd6e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cdi-apiserver@sha256:6aaf7b042a9b31d6538f6e41f524198e59a40ecff7e637bd89fe5a8a93f8ef09 |