Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev

Index digest:

sha256:43b09470870b3c04ffd52199f7374d792fd38c49756a3ecd1890435f2950ab3b

Manifest digest:

sha256:06ebb98631f7af7845fd9518526c6380a982e352bddb2bc13199884252d53665

Size

53.60 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:705ad615abf169bd5b757527eccdf9db3ac348040223da7eac5bc6f46cddfeb0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:a3c12c16338a2c14a7415b97bb04c3db02f0d9636c02f7e314738fb079e1b708
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:3e70767325195b8627493c3fc6c2f818ebea7249c797937ee34d9dbc1b76b945
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:f10fd2896cb0e9f3f4ac1523a7dde7496d598a3359bc3e06ee57217ccd5e2e0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:add4a1f9784d4246a15d4443a368fcfbaeb7315092fa16acbb92fc20ac01cc48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:d725ee2bef04036a1579ca5ca9c22612e79a8d51c4b9c08c3a69abaa283959dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:738c3da9a311cc83eac23ea87300a1c00825d9522e332efbe6cc07f4861cae2d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:55890c41d4104043de517da42cfb608f4b12824764915707714b02a2e650979b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:6165822ecf4105b54e725b00c9edba36cab8274e2bc505385d5968a0e04d0db5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:da264d9002d3fa971bd0ec53312d5a5397a055f0e146a830dd89c0d0749dac68
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:be54d7d56b7e7209c6283517133b84f95efa796b3138a0064d89c73f08f1305e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:95b7928585b9d6e3b33f4d88d91c043733867434f5651a7b8bb747e6ccaab1f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:cc9fa76bc3c53f14ec0cd21236f44d1de63c1b36c47f815544876f76ffa36a17
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:90b8d90b54c489b79bf7bbf575f082c98baa454692599d5b6aa4d107c6a68a27
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:3ace2686c1aee2020be4870ea7a7eff97f64850475ea43b6ea6c7cec48626448