Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:1a95c53cfe36839d217db36658b3a51367225216d2f828d772a62a86a45b83a9

Manifest digest:

sha256:62593a9b6b62d8011ed0accfb8ba3ee4df6142f65bfe5a97c8cfe54eef98b5a6

Size

179.43 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:098bb5030d82ed8743ad95be7b2b4ee573ec44a407887599f3fc113bfc452fb9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:97a89f8b42dd8e83c0f7cf61f70e677f0378d203c2e9c19413bbb7b9070ebc4e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:835683f20d1db5ed9b6151f92588d28f02b6eb93f2f451c2b5613cd795b2cdb8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:d18a6414dfc45e996064c464a11cfa09c1c4266b2bba62b0e0fb094ee0db3ab4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:43c7dc8263f697e53a9a984959a29d9c4c39ffb1a8d13c2f9791b689d89cb972
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:01c476d7ae5c9f172079fc24e49ce1a9e385315d66368f9d7d2b76d154a0f94e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:3742cea7ebc56568aa8c2dd45d399402d40580b8cdfee0cf3e2b318eaa8465c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:832b03363d14f74513b5d7577d4359856affbfba3d903ac5bd57b002011d84d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:13d5990cb9916618903118a89f22fc28358e446f37d1095c830ab1e142a81a3c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:4f8fc74948d63fef807445a38e6468a8f4686da4c3e26f98633f17e5fa149ed4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:72b46fa8af17169f5edda71b3f5d1e99edeea45c0b9fe59703490e0bbc3fe8a2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:79ee75de8daa0d97d3c9e25b51a87930e7018ae9f86d0af5d7e6fc8f55b4c7df
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:67c710551a06abedf7af21051fb4cadf61928e23ca978eecf0b4b30628141af8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:eee82268bc3838e733304270a77b930e690292d8b4c6ba3b7be2262ba79ad5f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:8316196c6f094848f087e3525a6d55afbedb6ce407f920ac087fc7914ee0e140
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:732951f7b50ac21eb74010879aed46ff9f509b4e59d786190c78ae0ddb6de8cd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:af6ea4cb8f5d808f62c870afb58726f043a8c08f51b540c5113ecf34c2dbe504