Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:4ff929bd394d9edba82f8117550931bb4d817eb8f087ecf7966f80195b806069

Manifest digest:

sha256:d5b86782cae7bc7c599dd2ce12b5f78b7bd9059db2d7fb3298b78beed6dd3273

Size

26.29 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:6ef1f73a27efcd3b0b3c11e8ecaf8c21b6dcd619e0cb76f3e49d71d6a01ae058
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:33949a444a3d70ac74e432a24de229a2fd630e70095436f8eba32b2475293d38
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:7a24068e50fd9309231037be0501d1e7ee516490ffc16a4d6447c96f74d31c52
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:8c98cfe319ba99fbe58146c4e63859c309d852284eeb97ed3e2b78f14433d0b5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:d1207d211bf390f7cb15d8ee1060a2f9743bcf8dc81a3d6bf3a0308c164190ae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:23b309e1c70169e0bb4e29cbc1bee64c92b426c8c9e6ec6d2e03fce87b54d184
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:a5645c4995d244d2932e8a3bc9728d96a80fbac29425db8bd2cb878bc8b07e34
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:63c7f7f4be7b1ba2a0914ac23be2a986b73e892a346669e4e5072cb5c7173654
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:e3d25772d073e441d29baa0ee85f44bc7e98775dfb890be7b9a418ab7b436502
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:c804fd3b36167b99ba4002464c5f79b046eebc784bb4bceed86c0366c50221ae
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:110f71098159662dd4e304cb09c98ee63ae2e63505b69b6d80e4337a618602df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:30612b7e5a3e2e5ddcf79feb60834e7269852b7446b67bc62eba749dff805359
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:3c2526061972a4934cb703447090b4074d69b9ad0189d654b10587e2c39a4d94
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:b62503f7f87ef355b43d3f389c66c3531ea85f222330173f2c0c290535104dc8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:04571cb7be76448838eed3899fb4aadb41df6ce9db16c3978d06ada09f93129d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:ac30c02158dd3927f745ad22008d47bfee91514366c0eace594ef486f77740b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:36643203fb025b784cd7453785abfa05c7550ee32331e77d13dc4243e1682c6a