dhi.io/cdi-controller
1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13
sha256:2e885ee5bb63c45d086909a828a8f398fa8be63ab7cc024b11687dc398f94f4e
Manifest digest:sha256:8b65b30ed1d3dbaee0f19e99c1730372283403b7f5ae75761aa35cca9105e9ce
Size
24.75 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cdi-controller:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cdi-controller:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cdi-controller@sha256:0f8bc05907fedae6f2dfe6c53e0e051257b27436d07b9f7fec0b05d74cfc76de |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cdi-controller@sha256:cfa884e95c640f6b6d006804be9f85297d166301e42bd8a0e7430f8ffd70b804 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cdi-controller@sha256:21754e8003387946db892af4e80850f2e238f78cf2a2c9fccfb76b798054e615 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cdi-controller@sha256:967858cc91fcf7b1c4c7dbc6da44c3430f3b7679bc93c91229a07841e9faa796 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cdi-controller@sha256:be108356df93d8743b51f38dbe69a776d92bf577e54e841df5aa01f963200ba3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cdi-controller@sha256:7b38ee5972aed9c99b709c037ea5393aa36090ada31d7ea6376878871cce9b2c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cdi-controller@sha256:7ddd02e027f5a9da32faf5d685993e7878bf5153ede8964f77d06fbec0d94318 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cdi-controller@sha256:ce92cf040865af565931f4a162a37791e58546fee1461b6a05bbc79c02f27c6f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cdi-controller@sha256:fa278843c067d2f79b2499ba1bd8d4c79a335d4e711b5bdcc231300dc8f18de5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cdi-controller@sha256:22cd97d83693b26ff75fc091a08cdc91bfbfc9230ca04257a3de8e8743de18b3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cdi-controller@sha256:116d9a6f49b0ed6f9f19ab53f35b523418674cdd02d65c9d17f3e26b8f578278 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cdi-controller@sha256:f503074bec41243cf9408390a8c2691741caf741b17680a6752c280ae7fc67a1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cdi-controller@sha256:27a20c8e0323944ac0604bf4b581ac436e031509bc36130e2182d9361ff969ba |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cdi-controller@sha256:f25ad018ae8d2c3dc73c6df4230dfd0d66b9a406ce63c484a4302b330a91b9a7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cdi-controller@sha256:868f84db59750638978791590a7eca8fb6561dab1bf9d0010516a6cfe9636432 |