Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13

Index digest:

sha256:933e751a97468e7994d041c1b6f425ebd74a1fb915f9befeb47633366d92ee9f

Manifest digest:

sha256:57814f8412fc5cb7787869850b3e0c03cbdcec884308d5c78cd71d0beb50621e

Size

18.31 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:cb6a227b021d1e8273f7bd37c26bde04b3a2524310f019418128a8404313d619
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:60e29fa2e7008f9804df63caa9e8acce3d8b6946d7be4374d7d3e0ca477beb23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:2ff0c29f683f38c19310aa4ae8d2c3a3bba122ce70924510028a60331a96cd39
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:2c09d2f6e5d0127d49510f379ffd0546fd614e6a776574b5254252bc157c0e79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:3881337775ef522f4f0a36120b3e933fbf76c6f66846be0352ebfe61c8b4ffa7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:34525691685d5f6b7998b99e8a5a33328953c6eafc872e1c204524b67a4bce68
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:55b3c7d06f726384dc3b22a95147b641135dafc5dfbd281a527d7578ecbf18c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:4451f28c3cb7f2b165eb77ade4b657319e21f87caab8706875c2dbbec19b7661
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:9f272b8cbd4d352a8ed54f260075b15fe7a8a741cbe34b62c3ee2afd298238c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:16aab026d86b11c6caa39ff2b3fe3b093015ca68d9f0fa2e3dd4cc50ec2021ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:39d447882ccedec4aafe0376e7e07054e70b6978c3ff180f883c09fcd743eabe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:1a577f922ba2bc962fb575a89522276bb178684e6dc5b5c9d62372cfbc347984
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:83643a36e6d266519d8d175ae7d0810eb6742c77559b8a74885475eb629b6c52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:2b423a12fa499d1dc5b6fa566cf25c924e077499b3c6bf0103dceecf4f76c104
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:c4072ee2180d4965e649681397fc7b141fdc577e2c740f6c4c5510185a4cbd02