Sign inSign up
Crane

dhi.io/crane

Crane 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.22-alpine-dev, 0.22-alpine3.24-dev, 0.22.1-alpine-dev, 0.22.1-alpine3.24-dev

Index digest:

sha256:c8c3a1a5979f0779abd9cf6ac1dcc4ba56321595552936d6d428d2162aa4115a

Manifest digest:

sha256:85e46c5425f2a51502dadfd8a0c1a3fc41e1787186fbe739c988b8ed96b667bc

Size

7.86 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:f34ded7d41faacbe13c1cf02d86dfef5bf1561a2f36dae880a2735fca573b891
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:dd737204aede99e8bef7a87dbfbba99aa5773acb16c88f3b6b85a072cbc101ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:fb7b8e1f6e02e0ad60ca1caab44a7f80bc6c47100c8b203eb9f2ec60b763e622
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:d2d26fc43ca3cc112f4d57a54502ade816bb7f14a982efbe3d8c42cd970f41c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:c94ade9262da25620d483527ad19b3571b3333df9a96c7e9ca7a8d77d99daded
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:287d2449bf988e79f7add9c2dffdbc8e3f8cb9e5306a3c074939adcd618ab196
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:75f9659473f059c2a3ae9d37657582e24d9b5d848bf81e4b2892be979060b0d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:ce08b5bb9b4392dc239c35ea425b4a5592ea2da04e3973bd3e76dc6ee1e587d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:d4d0acac96514cae2a3e81ef76f5bdbd16c29f1bcd7235c67d6ee19b4c6bd187
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:57c27dd157bb072801b67ec6380fdd3e8913d5059a6d222b48dca331bb2182a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:ccdd2db976b1433d4c093c29f08ea4fc0be1fba9677480666941c82e486460de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:218884c98feaf5a074d56445752b3bc73d4ea6ec89e297fd6506bdbbab6a0a06
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:c273d745552da3c554c9075f12b86c579029d6dbcb124a8ce8f2afcc1e9372ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:590e1fa69c0f38dfbf5809f811dcb045484cfb1109cf893d4fedcc01db7e289e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:111acea0bcac6c2e772e9e63b59a7190549fd77a614969070a6d20d5ac00107a