Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:f8d61c6dcb38f342bb1e0cb575435917b1c06cbb919478f32c8a5df19ab15c9e

Manifest digest:

sha256:0294e310917c1be3fddb84e04c8cc42c944bf5c20397aa3131e024829a201ae4

Size

54.49 MB

Last pushed

21 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:4a99c4aac5a43387f7f3cda89b62ef4efcdeab2c444aacc7923515487f45e958
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:3c4a77e5701a9eaaced02524427c265f785d16e5f10fab863caaf3e68017507c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-controller@sha256:ccbfe1ccb7427135f5b18c61098940e824b73875cd8c6db123480e39027d9301
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:3544af568c95427b4b2662b8cb51a5062f2d45edbe9b028bb162c84449ad20bc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-controller@sha256:12b3941274a26c1002ea5307d7b3d28a2706865cc38e9e616092d6e7523322f3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:2312e09c4c33d4587ab12a6ac9b9487e4cdee5d34f09423dce2c8fafbc49ecb1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:8696c7732bfca2a3ee302b960d1ce478e621f6aa20ff8df143a7195f8c533908
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:f78041eb746346b703ca6bbd7b768caca0a23c054ff021ff59fd4b0663f845b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:d6a258356efd9a834c6e0ccb601c33575d9948c9b00bc94ade401c4e68dd536d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:9158de166d51a704fc6cd2b801fb46f98c2d4aad646bf78dcbf44834bbd7d13b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:18fd1e2ce77aac5f984dde4779cf75662c5904304a6a15962495f2f2d335d3c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:ee785cba962022233a0ec14805d7232e77f696b6498a0626e8da705ef6273631
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:fd558eb99a4d51b284c3c544d332124ddffc5a279ce2dd5dec082954e7ce2998
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:c709b9d37917ea959431f981adbff1981da86632696ab365fdeaebad11e7ed70
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:19a12a0d87b03c1b78f3fbce107e8a59649483e550be7a650c072fcea136ef37
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:275f64d09420ce0c6071536671338475dab16dd4458eee733db7b0926dec27e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:ac4ac79279757ae90a0791a19663d1dcb499a9c5e190d548d55d15a234c47206