dhi.io/cdi-importer
1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips
sha256:9d4fb37ae7e8ffe279d2faf2015ba29f04b3b89e9d4e5d7a344d1107a86d8ce6
Manifest digest:sha256:e8ea2bdfbdb990c9e313fe16b4eb6c4cd4b05bc0969b9fc18836ddc912e7bd5f
Size
100.27 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/cdi-importer:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/cdi-importer:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/cdi-importer@sha256:a6365aaa70f0e81800cd5dfdc24cc22d69b3668aafd9e2b6d59684fa9dc002d5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/cdi-importer@sha256:e8b2b45578039ace54c679b690302b991f60b4b6553dfdd16fab05c44f4bc9c7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/cdi-importer@sha256:d228428042a2c1ac9ae7f6c90acb8baac421e598a6e086f57361ebf2ed754615 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/cdi-importer@sha256:c188b4fcef0b1ce9e91f74edf0e01dae7d72f22cec0901e69556f3468c8389fe |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/cdi-importer@sha256:e5871084e644f72d89135fd2e463d8039db18fdb722b29a3c00cfec1ecd1d96e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/cdi-importer@sha256:8320e081f3cc95eafc10f7a2378476ae67828c6252ae855870f39a908834886f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/cdi-importer@sha256:200b3c5c90fe828493428ec239685aa6ea2764696716ae530009fdaa3f7906f5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/cdi-importer@sha256:2afd97ab6fc25420e5683c1fcc710064979905495658d37a2c9498cc6444d624 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/cdi-importer@sha256:6169e7cc13bea9291204bdba04dc81353ae715ac8081223396095f858f42d98e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/cdi-importer@sha256:b991e579223f3373c3b1f8f5889ad2fddb87aca4ec51f1b09b654963ebd3a27c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/cdi-importer@sha256:70f52240cf834f2a1e6b0af046f3f6f26f478ab4fb90ce2806ea41aad188fd0b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/cdi-importer@sha256:be186e90dbf2131510e2805f0dcd42b1c8e463b979f11dad549e5cc7643054d4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/cdi-importer@sha256:d86e61af522c1eec5e227d0ac66eadcd9f3ad051e5719eb015c8bbffefe2408e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/cdi-importer@sha256:cd5089a8782893fabd990a14681bae26e5b3f1847469fbc26453d584d8edd6a0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/cdi-importer@sha256:1a7be47e8041abb50109b90d12fde941f51a6b46f84e8fa3df8294ec21ba654d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/cdi-importer@sha256:e8ed569c77189a66fc171fa1cc83e33ac55edd86f74e329d3bcd32692d2b36d3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/cdi-importer@sha256:5cf7a0ee1a922acd8740cc99a6bc6620bfc505f5844a8ec4d859f13fd8490706 |