Sign inSign up
CDI Cloner

dhi.io/cdi-cloner

CDI Cloner 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:e4a896e42347c5e78fe301de23810d96c37e1f0114215511cd5a0a1ef691f260

Manifest digest:

sha256:5890e1db7e7fb4ffe527cb04e65b077fa94a2e10e822d106b0e3349f3bd7f3f1

Size

35.89 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-cloner:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-cloner:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-cloner@sha256:c25aac20950859291faf30d4bd7cc84d45b189ba715651420ce152f3c1626464
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-cloner@sha256:2d68faaaa1b822528a665bd0bd89472f8a4c9490cd07bab56b374667bb61e3dc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-cloner@sha256:16c0b9356ac8041f75665d74b0a182d014a25a12558bdc80edc780323c690b1e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-cloner@sha256:84f7dfccb04021422a6a471b5ab73e23473e80a3b6bd3b04d7901531a937665d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-cloner@sha256:c76fbef59bbcdc2f3b5c0dcb8919f3a6156dffa78e880dbba4919be4af829ce0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-cloner@sha256:64a3ba9b2b01e719ba6097ee8636e66d3482d7c56ddbd67145ab07048e656bfd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-cloner@sha256:67918dcb9fe43b5d1e00d831c897451a01cd52e4e12cc557f6deaed11d528c83
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-cloner@sha256:eac34f8a1dc07108fd3e1b22ff8a4a9eadb275de17539f65d370de6a71cc9fe1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-cloner@sha256:5c6c96f1339928feff014a35b7eb317498cb8331e2e3b9e023b59f9961a0026f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-cloner@sha256:ae6a597a5340a6a82ce604e63db12389233cfd805042664b183a22463cfe0947
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-cloner@sha256:46e5bdf1dd0ea861191c0bbdd4c6b71271256a62375b2aa862e732879820a00a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-cloner@sha256:c22361e6a0ccf1b2bb7c2988ff6f2a3896956a200978bb33e4da557440944705
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-cloner@sha256:34993926ce865501f7786a580f165ab1e817a695edd12fa4f2a044443c8e53c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-cloner@sha256:c71072f4661f81d2a3f2ea2049bda5dd4c5190bf4776076835e561d9eba72523
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-cloner@sha256:1d1439d3485ec4979f5bf8fe18e49e0ce42ae2eefa775610b883b79c3a6bbab4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-cloner@sha256:8eff1f45b261127c742451c1e48f9e0c6a8be75fde76f05c896c2a3c72c8736a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-cloner@sha256:afd346ed55689e49bb529ca7e90dfa8b8ffb579637e043965c2c7f0526fc157d