Sign inSign up
Crane

dhi.io/crane

Crane 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.22-alpine3.23-fips-dev, 0.22.1-alpine3.23-fips-dev

Index digest:

sha256:1199cdf2f312321accce6ed21bf43c534e16803215912d9cea70aee62f838f53

Manifest digest:

sha256:bf18fbc36c399d28e7480a948e99d8246a5fbc7d1e57a3eae6b1e5ec70733c61

Size

8.70 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:2baafe3c6e9facf2beafcb5cfdc32da68a5d78d6cd27838403f996e05981b230
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:18fcd0ba2c349969068c0174bf17cf2fc402bf77d1f036731bf1abad70ac81ad
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crane@sha256:0268c53872ac04d5658c9770ac82fac1c086c04e23f36f1e61fa3c545f09b9b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:6db9efa34496bfdc7818afa738076676d4fcd48506112967b82f61a1681aefd3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crane@sha256:519abfcf8cb82e10096945f9f5543e69b28a6e5b1ba009fba223fdc051cb40ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:5649f3599dead8eda064c8e39e279f8e6221a7dac3fbc53aa331dc4645fc724a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:b38b8480a751613d45ee9cdfdebaa1447ace9990845588318364e536080af0a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:0d930f91bb115028f7cac5f76c379610275ef44a6a735a46701f9ed4f817e761
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:944684106b16282f705a1c730484095963baf94079667f4ee57645b658fa4fb9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:f7261b8e82013ac88fa47c21b179775946859ccd6d590159e6fba9b1d72dba32
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:5da4d989e6685074eeeb68235f1620290f2bf91f86caf431907867e901c05959
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:7a9acca35263b6b76cd93d040d57295699e6061d0549fc937ebebafcc497b13f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:0028f8cfd30df725f124badccdb33605d98aad1abfcc5eeba07fc957f4ff5e8a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:4c064d18d547a86f2a31127d059af6ffbda21f0fec852e3c1c2e8142a4ee0971
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:33e15936620c68e1d101d740482878d9f261bb4751cb2e54beb98d6a34eb2526
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:f895a0e6a639c0d68d73f48f0a85a45391bc590e613fb1ba272b9a6c716b3ab1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:d7af554be73408e5220295d3c529514fcb7b7358e2bfcd3afc80d67ae25d7d69