dhi.io/cdi-operator
1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13
sha256:933e751a97468e7994d041c1b6f425ebd74a1fb915f9befeb47633366d92ee9f
Manifest digest:sha256:57814f8412fc5cb7787869850b3e0c03cbdcec884308d5c78cd71d0beb50621e
Size
18.31 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cdi-operator:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cdi-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cdi-operator@sha256:cb6a227b021d1e8273f7bd37c26bde04b3a2524310f019418128a8404313d619 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cdi-operator@sha256:60e29fa2e7008f9804df63caa9e8acce3d8b6946d7be4374d7d3e0ca477beb23 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cdi-operator@sha256:2ff0c29f683f38c19310aa4ae8d2c3a3bba122ce70924510028a60331a96cd39 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cdi-operator@sha256:2c09d2f6e5d0127d49510f379ffd0546fd614e6a776574b5254252bc157c0e79 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cdi-operator@sha256:3881337775ef522f4f0a36120b3e933fbf76c6f66846be0352ebfe61c8b4ffa7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cdi-operator@sha256:34525691685d5f6b7998b99e8a5a33328953c6eafc872e1c204524b67a4bce68 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cdi-operator@sha256:55b3c7d06f726384dc3b22a95147b641135dafc5dfbd281a527d7578ecbf18c4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cdi-operator@sha256:4451f28c3cb7f2b165eb77ade4b657319e21f87caab8706875c2dbbec19b7661 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cdi-operator@sha256:9f272b8cbd4d352a8ed54f260075b15fe7a8a741cbe34b62c3ee2afd298238c4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cdi-operator@sha256:16aab026d86b11c6caa39ff2b3fe3b093015ca68d9f0fa2e3dd4cc50ec2021ee |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cdi-operator@sha256:39d447882ccedec4aafe0376e7e07054e70b6978c3ff180f883c09fcd743eabe |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cdi-operator@sha256:1a577f922ba2bc962fb575a89522276bb178684e6dc5b5c9d62372cfbc347984 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cdi-operator@sha256:83643a36e6d266519d8d175ae7d0810eb6742c77559b8a74885475eb629b6c52 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cdi-operator@sha256:2b423a12fa499d1dc5b6fa566cf25c924e077499b3c6bf0103dceecf4f76c104 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cdi-operator@sha256:c4072ee2180d4965e649681397fc7b141fdc577e2c740f6c4c5510185a4cbd02 |