Sign inSign up
CDI Operator

dhi.io/cdi-operator

CDI Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.66-debian-fips, 1.66-debian13-fips, 1.66-fips, 1.66.1-debian-fips, 1.66.1-debian13-fips, 1.66.1-fips

Index digest:

sha256:3fcfab4fce2150857b04aeaff54328ac274ab747efa799169a17e5470204e356

Manifest digest:

sha256:f02eaf30332caf6817931b3660e7eff81b0ef400919d37594ea89ab0206fdc58

Size

26.29 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-operator@sha256:ccadc72819027a3c6463c6704d2ccb389aa8f4394cabd42c207950b1a8653bb1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-operator@sha256:a6cbb51f29615dc74618c23cdecae5d136663cad0e5e9ce029a8726565d0919b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cdi-operator@sha256:005778d9ddfaa3fe89a7af9ae77d705a72609501e3017fe18fc45987a79e3a57
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-operator@sha256:889563027925d95a715be8af5d99952ef0037c5bebe5ca8e9a5ec6e13751b372
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cdi-operator@sha256:8a6cfa3a8fe08fd5aebb39546ad329cdc0237a3d02b4cec0d7941a427777b993
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-operator@sha256:bd6d8b77c756043e85f462e99285334b024b0005949117f90e78bc4c35ca0b12
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-operator@sha256:56a48f125a22e7cdc9fb0bb40ec93dab8f518f3142c8d2b4b4996c63a087244a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-operator@sha256:99e9310ea10b2f20b7253404f56b57a15cb8cea16b5785b314d8c8d6e52c329e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-operator@sha256:e779d5d8916500fc61d9a91ebb2ecadfdd3bd162bd8bcb7d06e943e717e094c2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-operator@sha256:a26f0dd8f43bde84c0c66e54e18068c437c70efc56d51769315c70038bdcbad6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-operator@sha256:ec7c4d7fb14bdeddb0b0a26644b7df62c3c1936eacc03823813cc3cc1f7c85b1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-operator@sha256:9c433070f2f5f54c6754d07789f1971b3b30ff5854a7340fb791e4864d5e89ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-operator@sha256:cc11069018fb64c3c21df9339cc651462c03a8d23f3828cdd7889d4d8b781527
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-operator@sha256:3012174e5777961d7ea9d21c7b48c9250777767c4ac5b305e2ff32e903e7898e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-operator@sha256:5149f175515a3e5b139ed6339a157435f3a15154a33b1ea80a119e167b867ddd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-operator@sha256:400d00ad774a3842b57b6ad8ae5630c3c2784afd8e3a6e48f4452517e1238e64
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-operator@sha256:ccdb56cbea4e4286c68a01a7e8ff57f028591c37706cdff7c7f2891a57c12f60