Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:6e6c3905f6996fcfe300e3fc72f3dea075bce4a1520ac3158c260dbc1e681216

Manifest digest:

sha256:57d6326254974816ca83d85e7b36c8168735299b04106405c01b1ad5c662ef61

Size

54.51 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:266a74ce0ec407f8c7f388cd095f2a18c60a3b6b45f81692406f50e0ec55a87a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:826087658af0d4b331c665b9b2e8e2531dbb0a8d8c567bd642d74596d256e1f2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-controller@sha256:18d3c24ff96d0bbd959c363961cb7f5027d13928aae87804e400803582669ed7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:1ed181dd5db8b56109c0fd75f8ab39985fa6c7c723a20a3c6e10fd0f3ac49195
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-controller@sha256:4526fcbb6d75397988ef8134ca274c4b3c986fecbb2dece18d0d8309342993cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:27054cb8a08bd19eaae653ebd5077d71c9b0e06882818051e3e5967aba800fcd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:41154b9dd3f4c81ff25b6c820ee99bad5f4568ceca6538e13dcf940863b2dda4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:26d6c4f4bccd12b90a11b74e8b27fbf92a3e017aabfcf0edc26d06a09d960e8b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:113ec639480fa43283761b5ee60c35f587a1c473cf4c93314abf22a84f6e1666
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:7e8d4157f567f9300ecdff5b2eeddd6e20f8b7e11f9fbb2201e65963cd34c5cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:3d28362c0fc8aadcd87dd3531eb086ffcf1f9dcb38eb71333cd6c895327e85b9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:e3f590154d83f5e48a6dd8607c324182d234a0b8519aa4023600c0b4eb4b0e12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:fb6d88d2efb921a7f9087ca9e14d927d05a98712ae52227f044b3cbcf7e8c7a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:01625e1d857d5f272b5fb1b07775549a9478d5da57822a0e18745fac61fe4510
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:a1f1fc8fb4be91b81396a7d9bc7a5f54fc9122effef4a6416586a3364b9c7983
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:220c5a741c41fc5d4def42d035ecb9110a70f1610f530ea9f2e532c1badf47f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:06bbb7c860ea21f6115c85c707ef9896ae0cd1374ef3d076365f31cacc17582d