Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13

Index digest:

sha256:dc45af03f37271185c762084b412845a8527a6b3c185f66fa052c50a6ea6e1ee

Manifest digest:

sha256:2f271bb7c8eff02cefea1c8deaed926d69a13464f0624fd7a523dd6b3d6d7c91

Size

99.52 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:63944b25ea8cb55917a0c29d36fde7af303de7e6f3098019f11e1ea8684f9c54
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:9ae361adb248487ea3571d21912b9f64a95172173e44f0d6d068b731a3b472ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:dac3ecab5f19edf4722a05e4914f26199c4b12427a6333e9b48fb414fe3eeda5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:5caf1391d463c849e76767290f8e88fc6163f4ae3af1060d8792b7dc37fa23bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:95f9b18177123dc65ad92c500de8492c42fc872fab703d9643dd720b1061ab8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:8095ad5ad38feb5d974a6c7b0d654f43fe8328ca2789959ffb341864364ffafb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:412a82f815111aa7a1fb118c43c4d1f22edf1f38978aba5d83f39aa5b9d0b95e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:8f97b91cff70dd2523912c1ac9919879766d63bf844772df3b50d7a00d2433ce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:fb5c308fc63440934fa65db6213069b7167617dc767a69d603bab9a40062679c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:e5db737142fec814a87e4217a5f7a8cb4168ff6dda797ef13c261cdb7ec51bfe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:dba00019b2b1356680d1a03a53170166560a17a6f8388f5aebcba526a54b3d3a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:5e05a2847b7de6c030636b68251120ca7571601e3822579aba7dfd1c51d9352b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:8ad873e0935eca6f894722f23b3703a3f670eeb089e90192f724a139cac53a99
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:a87ba7aa9e4a460884c90407f6e362f998ebde43c6a7ff51cd694cb10ee97acf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:de7d4f31558f4bef98a3f7af9bd9750ab148ace59053158517f916ee659aca63