Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:08294250fc9b423683097da3e8292f0ae1c35ee00b771a99a98b004ed1a9e9ce

Manifest digest:

sha256:53eef492815311e4ce76c8165acc41cbfc5e7849f6fb1d96c0334bdd658417e0

Size

187.44 MB

Last pushed

12 hours ago

Vulnerabilities

2
4
1
3
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:783961fe8ae9d65c37e4e2ac4ff9aa2dc5faf33015ded51c5363947aadb7f010
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:90fee0102499403d807e27108c5beefa7f6a6972922da6ca1ddf3f4377b1b9aa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:0174ec143c487b32abe18af46856b7bb579cc9bf99ec142fccf2ea5df4f73205
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:352606944f3799079c038499c082517738909551ecd158575129a21b36b2fe06
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:a54947a381c05db4282dbb1dbab8cbbcff23d90c6e6c135adc81696e182ff548
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:2561c3e3006a001379eb766e9a4c17649edb666358c89e0b988b7f75e0fb63a0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:6c41747833cbeea6b4175760384b630df5d8371f9552286d690a45d9724e2293
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:559c65ef33330268be3d93d8cd26824d9dea538a2eab48d28bc383486d469dae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:0b4d71d0dae1f32e3686ca1484162e238f9ee32e7adcb29577ed92799640924f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:aa9062b38e78cbad270b5e0cb3b7aefa5cee903606ba2ea56312ee56f3db6b10
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:20c77500f5c683d1a0b1d3708a89e76b4e126a65f2577e325ad28baea6cad2ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:3d928822b30f15c13de44735d3c6ce22ab43958334361f43218798eaeff558c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:75ab1355f66d3588eadf252d9aca3686949ab3ea3daa3116c98d4c27df91a7ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:68b1a5d77b20cec0f5160dd25f94dfe038900e8b26b95b9892b6b09328720bed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:ae5f0de2c5f51d344dfbdc316887286d55469c8281dd33b05df2af8c4f2f4b28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:a65d78a44081d65147db68b6b410a4c1b82bc6e8beb9995b79b319c914fd284c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:9276f33ce45db1ec5df054ec67ffec3e6fa3165cf4292db750baa7e446c2bdb9