Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:5ebb3af3c3558ca164a221db704fa607409efe424bd5aa53bc9b8f763bf79611

Manifest digest:

sha256:e091fb094822451d6eb839562396c4179f426f2a6081585cc85761820229fa08

Size

26.49 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:2240c12fdb19a35bf0cd65753c475102bea9f764c98c90103e48227c9055d0d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:6c84154dffa7736c97b23527fec3cc37d178a308e0c4e4f96e9c19fd247a1a2e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:bac96f42eea68390aa72ead32ed535a67337531e23ae6032e88cc2e4a5caf05b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:a9249d0d659b99601435d60403dec645d9375a9a06e6dbb5be8e257121312ad1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:3f2129cdd190969ca9f0ef84b5285de3eb062de7f0a8a6b023aa8cb4000c3d2f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:75e3e31a70e06fee106986f27bf64f2e89a8cd8a9646d8005b8439cced4ddcf8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:473c1d5435fcc4d9a6484cddd0809f821d980f405550b3a97e27b5bf9b1b1cd8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:f2be1b51b7812fa19f1bbe4fa1a3d53edb42645f84d72888b44e7e7362039150
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:59d7b624cdb2711fa38207ddb39f1cbf63132d48bca2079312ee869c6d10c744
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:0796d5e460944b05db51742a4ede9c582b79e4b412f90075292c4c1be5daa27f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:6148f52e54c0d93f795c903095f692cd4741139c02f3dfbe68884b3badef6f5e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:cfc7e10c46bc94026ff064cadf372d75107c09cdfd1a8d4927d6b553162a358e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:712e8a921b633b6e36c031c13424497c9d7718c728d7a954ead1e786ead4c53d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:bb159b0b2eae4ee428414ede6c95d3890b939e66de14c623ffe1d84053c45875
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:1c33e911e4dadd3ea9f3d613c667cd2cfb94eeacf82f51dd3c29d11c0563458a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:1c4497f3e87620f10281f8ee75a33ff16dd8f5684a10a1fb02b998a7cac333af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:de958ca8ce90e7b860bad35900bd05d9c88a3f55b73eeda16c9f6b0ef7888cd5