Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.66-debian-dev, 1.66-debian13-dev, 1.66-dev, 1.66.1-debian-dev, 1.66.1-debian13-dev, 1.66.1-dev

Index digest:

sha256:35deb0082e7f3067cef9e02cf6efc6cae2b50cabe593d297bc6473c65679e360

Manifest digest:

sha256:cba8b209d1fcd89413a012f4e4fb3d0c1021c97be68945c3ca07bdce9b236efc

Size

59.16 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:1e3d27b9d501ef74ae37ac894181c489576ae9f798e7e2a29cbcb73d94512a63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:7c90d2cbf6d0e11f96cbc43729795be85c0872a6294025e7dd8491b3f0b5e004
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:9f915f6a0a0b450999a7de607103c670fd590cbf24376fc0ac7ffb3fd066077d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:cc11e767a0580ad528fd553b87bdf609832f702154a20b55136f3aa71ecf10d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:104e5197f2940af679afa693cb6fa586cce5e59af9485cc654ab05976d20d724
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:86345c9899b59d75d15af84d671da9306b4d687d10c1a5e017163f3d9ef6216a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:ae255f95db0ee9d7aa9de4a1b03b03f74c97f4172e1d20c48d2f80dc38de470c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:4eac482873441652a4389184098f092637612f01b3041259a0b7adeefa31b77b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:d4cdaa522306cb0377b706e3540777b84fd7d6e6957a799508cd5cddb2cbd379
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:4bfb493674fb1e4133e4d8ed263a680c5518fbac66e37ba7e5c9a9224bb12a69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:e12d2d0e451c70f6d7b2a4dd65cbbacc0613582987b714843627c35c62227843
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:e7dfcc3cc9687a5ab85919d204b8d44bad0c8e48934c4513e5be5e4739717768
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:7dccbb245387653d322bfe20f256b3d221bc88cebfbca30a467800ca6656bc58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:4c3ea72f3935c13c23f7be3da30b8ab47ab3e50258c2e904c9db313f8179eb25
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:9ee5162ca9844a3c7eda2b634c4441e8d350d4557795e4076727955599804143