Sign inSign up
CDI Importer

dhi.io/cdi-importer

CDI Importer 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.66-debian-fips-dev, 1.66-debian13-fips-dev, 1.66-fips-dev, 1.66.1-debian-fips-dev, 1.66.1-debian13-fips-dev, 1.66.1-fips-dev

Index digest:

sha256:e60c32cf20fb3e40dfa8fbdb9e4e78ec4e2ffa4efc1747589e6bdebc77c4b4ae

Manifest digest:

sha256:62e9dc530e52f9d405ce1d5660c32d652f5c902319e62d0c4db55620bb034c94

Size

179.43 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-importer:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-importer:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-importer@sha256:2db79fd32d3f0ea350503d0bda6376612c8d5c2fe0d49ecdf92074c814845082
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-importer@sha256:bb35caea906162e38b96d2127673ea088ba7c944ecdbe0bd0deb177fe9be8a3f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-importer@sha256:76be264b2c04762c0cbc5726959d86490f6a87224976c4b2aa7cb032b1ab75e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-importer@sha256:2b6ff2116bf9b8af313648d3e71b7954900cdf63083c808ac8fd73764d873f74
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-importer@sha256:0b7cc84c2f39650eaf8cad3ebf060420cbfa810491323c09370d49a037ae90a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-importer@sha256:7c60903124d8b83de64ff5c560abcdb702a38c07c65bd3029e8672ab43a1b673
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-importer@sha256:3b812bb9841230be53a0bf2c9b517a77f61839b4cdf9657dcbcf255ab8d393fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-importer@sha256:9549f6b56b1784734277cfbeede24a72a51f2e33cab0c0cad3d31249c2590a91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-importer@sha256:9569aadc9cfc93f3b3ee137ee28cf76c1dc9e7c793cb09c78c04b4c476fa7e0c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-importer@sha256:742f8f4a1b4360bada24f831bbba88305296fa01a6081e90c1245f703a085134
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-importer@sha256:709b54590a99236812e161ffb17b18e609b13fe79962ca863c14872064622a86
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-importer@sha256:f50935ff68164aa149fed6aee200f7b87d5b0e764b7e7ca602178854aa1f655e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-importer@sha256:97fcb1ddb0d7e69c5c2cd55fa19ac47011c2bed03b689404d31154b754934df5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-importer@sha256:de1a612fad35a5b85610595b05c2857de230d97ab3ae704d4fd90d1831782796
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-importer@sha256:5a7ba333cbc278e021769efd2e3af764468ea4e15ccdf3f21a84c20567d6abf9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-importer@sha256:c4ad22d3e11630b241ef17dc89e73b0a4ec067283f579b7b4ad35b8b79f2bbef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-importer@sha256:8ea2e376289dff1b0fb9c671195c9c62e28c21ee1e3b78b9364199bdd9dc6285