Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev

Index digest:

sha256:dc7b7e8fe983146fcf2e91b0e45075b9ed1aca79307705ba5d5b3f6a770ea7c0

Manifest digest:

sha256:7e6e481c50798b1f0612f516b16f5ad3b431918c0aeba3c535036eefbe2b01ad

Size

53.74 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:1de01c26063f36f3c0311f54e6ca5a96a0d846fc8c68b73bbeb3323b908782b3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:0ce2fdce9461c72cb8172e831956b6e37e8de0a6236d0ee195caf0ce611d0024
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:dd24f7518751839c1ea671b0db47bea1ccefd557e44cdf620013b80db36ffea0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:fe521ef08a6cf488d4fe0fa34a9ec70d280d2c697a5589e8f5e2ae2eda1c260b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:07e374c07f8f7feb82fc5c5a8bd089d84ec0bbf2ca63a4eb60927955b962be97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:e3cf4f60f36a5c0c7a127b054e15513594e732f1ee0fd048c33ff6dea43ca03b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:3994365e8f00d686bb30eb690754887b15830e93e7b932c131c58e23b06998dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:2d08c463367fd7f296e23babe27d5aafa86c0ee5e0eb5297675a917c6f55152a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:65f0f60551775c5ffe26b025ab1ab42d003a245f20a316cfa6263e31755caa80
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:92743e05f64e0d9337fbeb7471e4521cbeee6c9294db1efdd55b00e57dc2ba70
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:5b0ed2b4276936cc1efb925a7e2c977507bce0480c9cb8a42227a22cef4f77e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:f137a09242986b6758f6bb0b1bb249d0ce9f86bce168e7f7fb670f7acffc59fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:f6f31677d20e82f2792327ea77f9c791cac413a059fcee262c27b4c0d2e4d168
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:7612ffc54dce7078e599b1ca8199ee582f985deaf96a1b0c2c848e841512e5e3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:ba91d4cbe93fc81f2fb75a1106ce59d980eebb315363bf0698a8d7a2baa6d809