Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:2c7ba74008a74cdb45a135e5134a6d3e632ad85e3f0f90a7b4218c10dfad7be7

Manifest digest:

sha256:2a34b6b8a2815d7bb070c7c5fce4ace0a5e55bfd5f2ca4d2c93936a69c03f252

Size

180.69 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:bf431ee811a25afa2972cb0811bc6c259f25fb47fb627de6e9720bee1e8189b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:8a3d98e80e9db8bd014890fe6350e1e69151fcded53efa8887d0b135f8dcfbab
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:2f54c16e09e9bcf468795f1e87a764dc43d19f40fde0048205062c1660a87906
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:874cd5430287b7e63fc764800930bfb066d3cca560af044f18ebe6b5b5eeffdf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:8ce4949e9b8aac46b890cbe39ea12ce9256f96b00e6b080839b8557e410e393c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:31a02fe6aa4f78c2ee55ad9e395752838943298fecb330b9df301b6722c0730c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:386638f5a5ca166b0e24f98d47cb330a7ac496656ad1f984d639a880df39b65a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:10df5a8a6f5af0cd7d3503cdaaf1e37d782026824aeb198d1a1c114fd392e885
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:a80d61676130e08bad1bfc00e1b02d739fef647b22f684422203694a5a2d7e4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:ac5c0249c5f15f5f066a4a3b42eeec21d00ba3665db0d92a7725e2be97a96337
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:630221e65889628667455002d6026297640e9b549e9bd5ecf6b741e9b36c05f4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:1b20e2aa03623f3f2c747b2f6212647eafb20703389e57b2a32acc05c2b58596
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:c7bddcb7eb07e857e203e21ad6cd6179df64d6239ca4e35f1a9d7af446d7428e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:42bc6101690ba655bba2ace4fcb88a7567a433cd04255dda765bc743c0823700
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:90d599eba71997ebcc968e6e3ff1f69d5f6f7bd1b2c12801b732f37c1098901f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:5422254aecd26ec6d85b58fc086c13deea128b73178730cbc156bb8716568912
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:da0062447b43a69b57cfe213bf23f6f019b1afd3a0eb925d415ef619cfbb1513