Sign inSign up
CDI Controller

dhi.io/cdi-controller

CDI Controller 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.66, 1.66-debian, 1.66-debian13, 1.66.1, 1.66.1-debian, 1.66.1-debian13

Index digest:

sha256:088827a7076f26d8308b222e19f6c027eee3431cdeb3008925d20bfa5791d892

Manifest digest:

sha256:8a88033dbb38bbc98aa1a1cdc07e3040b87c238a036b0315a1db48b84e87fb4f

Size

24.75 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cdi-controller:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cdi-controller:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cdi-controller@sha256:199c9ee2e43be9c8d4ad0d139c4b7f3a7b61bf259fd8d437d2056d11f5295183
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cdi-controller@sha256:22a8f39a49626382be8357eebbad66d9426f04d1f8d3dce4825a8556fd281feb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cdi-controller@sha256:4aab3b7f07d3bc6c031ee9fbca665698ca995e859baa50e80feef57ab43cbadc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cdi-controller@sha256:e8d4da8264a3274a08deeeece544e1e0158a834ca3cbd89e93451b255b246f55
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cdi-controller@sha256:5df84e96b6a0612b1ff4f78b97807c46e75e4a51580e0f884c715029807584bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cdi-controller@sha256:0254ed59782f6477ec6edd48fc6a0c1b8087b96928a9327d9c129f171f89bdd9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cdi-controller@sha256:e3fdd1e8b48b29c688536f7fc8f1bf317b9ba6ea15f501d81f0fc8bcc7729e2b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cdi-controller@sha256:95016e655424d0f614b94cb86b6d1d8d287b90ae9a1e5839098a6adaf5b5f866
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cdi-controller@sha256:56fea5e025ef5097a68bf9a38030b850bf2aad5a4c8f89deab84f18697f664a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cdi-controller@sha256:305ae84d0f0c550ed3d65ce61056135814e7cfd9c8d11c9250095e86e0e54011
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cdi-controller@sha256:00cf384a80b9bc5963f9b4764835c8e5dfbce256861f1141f958c3b81077348a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cdi-controller@sha256:5a5a8422a7b22192783fb5cebea894ee244bebcb7abb70ab9daac9646a76ca5e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cdi-controller@sha256:003648073c0a8c006f0b00af0ad436be8cc7f98c66f3c88033e3a3a9533b7ee6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cdi-controller@sha256:3369bc6376a034bede6c564d531e584be3bf0c13931350f73548c522530af268
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cdi-controller@sha256:448d8bcf6a5ed637857eb7ff8bca63964dda60081d8257c28506b364fd689012