Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13

Index digest:

sha256:2e885ee5bb63c45d086909a828a8f398fa8be63ab7cc024b11687dc398f94f4e

Manifest digest:

sha256:8b65b30ed1d3dbaee0f19e99c1730372283403b7f5ae75761aa35cca9105e9ce

Size

24.75 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:0f8bc05907fedae6f2dfe6c53e0e051257b27436d07b9f7fec0b05d74cfc76de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:cfa884e95c640f6b6d006804be9f85297d166301e42bd8a0e7430f8ffd70b804
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:21754e8003387946db892af4e80850f2e238f78cf2a2c9fccfb76b798054e615
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:967858cc91fcf7b1c4c7dbc6da44c3430f3b7679bc93c91229a07841e9faa796
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:be108356df93d8743b51f38dbe69a776d92bf577e54e841df5aa01f963200ba3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:7b38ee5972aed9c99b709c037ea5393aa36090ada31d7ea6376878871cce9b2c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:7ddd02e027f5a9da32faf5d685993e7878bf5153ede8964f77d06fbec0d94318
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:ce92cf040865af565931f4a162a37791e58546fee1461b6a05bbc79c02f27c6f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:fa278843c067d2f79b2499ba1bd8d4c79a335d4e711b5bdcc231300dc8f18de5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:22cd97d83693b26ff75fc091a08cdc91bfbfc9230ca04257a3de8e8743de18b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:116d9a6f49b0ed6f9f19ab53f35b523418674cdd02d65c9d17f3e26b8f578278
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:f503074bec41243cf9408390a8c2691741caf741b17680a6752c280ae7fc67a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:27a20c8e0323944ac0604bf4b581ac436e031509bc36130e2182d9361ff969ba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:f25ad018ae8d2c3dc73c6df4230dfd0d66b9a406ce63c484a4302b330a91b9a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:868f84db59750638978791590a7eca8fb6561dab1bf9d0010516a6cfe9636432