Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:cb619e3633f37885126952d47680c498c834fd001b8698a7d738494c7525a0dd

Manifest digest:

sha256:e64515ab30daa60a4085a60c4094dee2fb0609e3ae88765ad958855ab4dac7d9

Size

107.76 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
1
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:47758615c183ffa2bf447694fcc1a8866b9d77a5e2ab77bea060ab608a708c37
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:203ea124ea610332921545f953ab9d105ee742f039136961b1c205c01894541e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:971012d51917503d3478d4565c677b583607e33c847fd71d6212f513d1c524eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:48b33abf695f1665e55bb481e1fe51d9900eeae3b7e57700916ad7b8a49c64a5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:21708325246f7762bfb7fbcff7b1926917eb287c3b2bf53ff2fb5748305fd3c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:f7d4339fc539fa4f7e717f59b250bcf460d3a0a5a782d702a5644cadb5d5531d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:a9b031b1e1ccc261414cc9bf89a7f793e96845b6b33f2ed52fcd7ff909dd75a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:e500552e1cd67f76776638bdac5261dc393e7deafea6ecbfc6a267613ce9bc81
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:ae318cbd9c8d2e9e328528e0d2583092e9970bb0c3262eb6dcd3f1f82635002a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:e71e1ce32a066ca915c512f79b76f5cc518a862fbeefd3ad64c386a1b55bc22e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:dccfc5d9bdcc869231c858d1b0f40a1a3f01695b0df7d40a14af742316f04dec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:34a8a70a84e0333671cb3a1ae4275f3fd81da71840742286566446a9a176fc8c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:e6a2ee4ebc86d4ed914303d89b854e143981e56fb28dfd6836041ce751087257
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:54ad0618143399e0b42b77dd3350c6028b4c5125cfb497380915f8113644d856
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:c8c7d440090255e56934f728da341170f102680e1fae5342712c5fd0d63429e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:9b4de9214a2079c67df2f4f4034b1aadde7cb0e49ce390dd84f7ae76179a1275
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:4c9d76d8e8fda5afc6ec5a83c87ba9bf15b7302d8b37411ff8ff3cd73e501def