Sign inSign up
CDI Cloner

dhi.io/cdi-cloner

CDI Cloner 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:12bbcae33ab14e594ae4e9213026642110b6781ba3a4770073fdd01ed4e31476

Manifest digest:

sha256:7d5bb750b1367b2b272bf5ab4e902afb275627bdbf6ccee9ff6a5f4d0e60989e

Size

22.34 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-cloner:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-cloner:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-cloner@sha256:ed8a19e423e52e0f77389cb54ae38250755bc0f558b69abcf209f8bd1568d6d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-cloner@sha256:054b583e9b4da777e2d509228a2dd5b6d73766e3e76bfa88461deb4497e747a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-cloner@sha256:d75ec43c92a89cb6e150c2943bbe4aed0721a3391b3a64d8db4d73b481a4f5ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-cloner@sha256:8450363626bfb787ec58c54309d0d909f66e371334813fd4ef66ee940e3e97fe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-cloner@sha256:01bd4ca1e520f00405a52dbfe4af203eaa1e1c836534512ba70132e3857af113
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-cloner@sha256:32e7dc4d2dbb01868e6ff917b47c4e0b04cd0dc9019f48ea1a7febd55032a812
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-cloner@sha256:f3fb180d0874a77b036893fbee0f221cc2e93a1358519c57b74fa2553f22e502
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-cloner@sha256:7b5654aaca1c82b8add9a9e09f488c44e320eb01b84b584a202def6cf72d0cbe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-cloner@sha256:d6678760725502e26901da16ba69b225690b0b906d3ebb001b40fa16a8f2d5e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-cloner@sha256:90c04ff474d645db8773de9d87a95307631d857d61d8400c0a8d971985eaf137
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-cloner@sha256:8e427a9adb1209b39a1f6c1e805c22eea4080168fea086d29d53daa1800842d8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-cloner@sha256:e64544592d38c4f297234952b72b04ca2c19026771d4b183f0b412e7b8de8191
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-cloner@sha256:6544c539d51f2686e2905dd6ba5cc408eacc16808b0ced6528a71779b996df61
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-cloner@sha256:ae42ddc622aac81163b99345f0b1553ef1431a81c01dae66c88a8221a65e825d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-cloner@sha256:79e4708bd15717772e04c500f97843a9fe75ac39b0658b491b70c467dcab5fb1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-cloner@sha256:1efb5b65c4d69e86f4ef22b955e5c4e1df7743dbad5556cc8238b405e7500249
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-cloner@sha256:80aeec6ffdbc1a63d30c5277402b9176dc5fb6e514444f81a5aac101b5810fed