dhi.io/cdi-importer
1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13
sha256:dc45af03f37271185c762084b412845a8527a6b3c185f66fa052c50a6ea6e1ee
Manifest digest:sha256:2f271bb7c8eff02cefea1c8deaed926d69a13464f0624fd7a523dd6b3d6d7c91
Size
99.52 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cdi-importer:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cdi-importer:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cdi-importer@sha256:63944b25ea8cb55917a0c29d36fde7af303de7e6f3098019f11e1ea8684f9c54 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cdi-importer@sha256:9ae361adb248487ea3571d21912b9f64a95172173e44f0d6d068b731a3b472ca |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cdi-importer@sha256:dac3ecab5f19edf4722a05e4914f26199c4b12427a6333e9b48fb414fe3eeda5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cdi-importer@sha256:5caf1391d463c849e76767290f8e88fc6163f4ae3af1060d8792b7dc37fa23bf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cdi-importer@sha256:95f9b18177123dc65ad92c500de8492c42fc872fab703d9643dd720b1061ab8b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cdi-importer@sha256:8095ad5ad38feb5d974a6c7b0d654f43fe8328ca2789959ffb341864364ffafb |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cdi-importer@sha256:412a82f815111aa7a1fb118c43c4d1f22edf1f38978aba5d83f39aa5b9d0b95e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cdi-importer@sha256:8f97b91cff70dd2523912c1ac9919879766d63bf844772df3b50d7a00d2433ce |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cdi-importer@sha256:fb5c308fc63440934fa65db6213069b7167617dc767a69d603bab9a40062679c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cdi-importer@sha256:e5db737142fec814a87e4217a5f7a8cb4168ff6dda797ef13c261cdb7ec51bfe |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cdi-importer@sha256:dba00019b2b1356680d1a03a53170166560a17a6f8388f5aebcba526a54b3d3a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cdi-importer@sha256:5e05a2847b7de6c030636b68251120ca7571601e3822579aba7dfd1c51d9352b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cdi-importer@sha256:8ad873e0935eca6f894722f23b3703a3f670eeb089e90192f724a139cac53a99 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cdi-importer@sha256:a87ba7aa9e4a460884c90407f6e362f998ebde43c6a7ff51cd694cb10ee97acf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cdi-importer@sha256:de7d4f31558f4bef98a3f7af9bd9750ab148ace59053158517f916ee659aca63 |