Sign inSign up
CDI Cloner

dhi.io/cdi-cloner

CDI Cloner 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:51ba189d83abbae3a0f68e5f20d03c57cf4bb2de821f514779f397768edb34bd

Manifest digest:

sha256:444c83aa7deb8df6e3ca2eca7e4ff03073d1b1977feec59906ed412f0a332c53

Size

35.91 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-cloner:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-cloner:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-cloner@sha256:2184be773b23bc5ccd340752bc0b525808d6dd833132e6c4f19d88c9a51dbe24
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-cloner@sha256:d9c0096cfa752a256691d53eda0f688b172a272e043c58ebc2be2f1305692be3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-cloner@sha256:848dab26062add32cc4618a947c417c86c0f56392580d46a43b34bd3d7ff3fb4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-cloner@sha256:7c960426ed8d29dc8999d0a7e710cb6a30188aa5c29218ef183e94fa06861c96
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-cloner@sha256:9198c5d0608dd952e5e25faa3198cb5b56d7e31b2cbd6f213bb68bee689ea3b2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-cloner@sha256:0ed8ee7f709a359345d906e21ec35e58a98fc8dadb3e9dad99f0a73f939254bf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-cloner@sha256:3a6d39ae4c09814487a57d19a7976d64e022d318085627ac7d13816f08437052
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-cloner@sha256:bbf9dba15a41566d5e80a41e1dfccfd1dcc88c105a33db1c0dfe1ac567cf71f2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-cloner@sha256:5353a4c023a646ee65626207ff94a5bfef0839e63f94735036e6ce1c26c9c41f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-cloner@sha256:ae363faa298c06d2d7c28e623c356a11f1c8873c8ae239812031cf6706ec17b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-cloner@sha256:ecf1db22a614eb0f216d5dd19d42f5fc073dada09f14a05833f27b395c397cf7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-cloner@sha256:9a6387a4dcb0592740b35680701e1da224d72b404efa79c0d0bb8c19fc13c3d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-cloner@sha256:bd1a3a2d7badf3faf1c4f48fcb99f8717c949365c15b058cabdc8c3550df6841
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-cloner@sha256:2038a963f0434afca9a39129a662e6e9244be359e71e3a087f7d1dc3ef1ed7c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-cloner@sha256:baad3f1659e71df7c725cdea808bac7543264e847b464f8dc7ff2743a984a7e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-cloner@sha256:61cbbdf63312a5e78a9950113ff39749a69be105a204ac5067ca814b01897542
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-cloner@sha256:d04db85a554f36aba0d337757c4ce8e5f1b0f42c99681bc28847ca5447ff5c4a