dhi.io/crane
0-alpine3.23, 0.22-alpine3.23, 0.22.1-alpine3.23
sha256:8d25dc7b689198e79a6dc6c074150b36091c7c5ebb2d9f3385ceb0bb7ed5d2b4
Manifest digest:sha256:8f546acce56e5883a4d5fd4322b82dc1f6cb5cfdc65a34da60e79d8a1c9ff360
Size
4.49 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crane:0-alpine3.232. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crane:0-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crane@sha256:1f3ab9b34beb75875fe04db48c8d1ff12f5258d98a83525141f3bae748f779cb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crane@sha256:52bba378ad60d67cfba02923aa6ad9e45f46b5456cf7cdf8b3de392c9dfd317d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crane@sha256:7dddfe6039416979df06e4acf62fe9dac04b74a11a584963ce0f94b0ed6d52a7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crane@sha256:263c982726d73a99ce2bb4389ed6534330986b6578ea67f533d1266db679b50c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crane@sha256:3f6a3846805d8c754a2904a685ea95f2aaa7148b8dca4fae473b4824d7cb0b34 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crane@sha256:9d3c16ec398a54654cedaebcec935708e7a2b55f6a360951899994ece0de60b9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crane@sha256:3c18e9f71fe43abab26dc7c3d1529b3426e86805177affb2a54ec11770b7cc3b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crane@sha256:0eed05658b7550bc3bb9408be4d06e246cbf4152fdf467ad26d963ee2a7827fc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crane@sha256:c12a4ef57a459a69cd0ea602db67a35e6934f833901a9e76cfa98ef246935c4d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crane@sha256:609fe46e5674258ec751671efde516f1a394069510f51e85e06739b0a3e971f7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crane@sha256:0091ad9b603003446ac219ceba74bf82c4b62390e016eed2e41033bfaaed5120 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crane@sha256:98525022043f34cd250b1a0c8abaa7cdb4a8c118365c488b161e3dfa62ce3849 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crane@sha256:b00703b1fe60c50b0f56eb51e82e0396163c39d5cdb3236db73ff382df16f4f3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crane@sha256:e248486258afdf019aa053cd221c95154a0a28901a5ce925d11c8278d712e1db |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crane@sha256:4834fda7603286c7344b0df17bb5d37f4e989827a43a9407fc09fdc0e625a9aa |