Sign inSign up
Crane

dhi.io/crane

Crane 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.22-alpine-dev, 0.22-alpine3.24-dev, 0.22.1-alpine-dev, 0.22.1-alpine3.24-dev

Index digest:

sha256:e66f596d4fb8ac696cc5ebb78b7ba9a89882d2d057ac17de5d636f1fb83598ed

Manifest digest:

sha256:c19a54cc674067e512a29c58110c8ee99a9c4674289e09941d5ecc1ac2b6af5d

Size

7.85 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:377764d8f131b1301eb91d683a74ddf70a76c38f4f7d9dda303c806c84442b50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:4b2dfd1fed3a943fa3267a2f67af88ef84e1a8ed18891a9005b3280b3ab823ab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:6bd458170a458a940ce27493ab768a2ec74648036220e09e7097bbde1d684dfd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:23b8f20e2b9e52109b7f431e42fc4afa36be31a804f203c9ae61c797ea64f741
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:ed13a06a372388dc54a80d73e43ebbdb24523f76ab6941aa36ab6f4cb20a4484
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:f53c121268302d1b596dac2a3df994616d5f1f74d5e61a19c5a1cb80e84787a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:10df797a3da76a5144201dd94e17bab00909591071534ccf222ddafbf4ed3c5f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:e7501c6f976fad47306169662f8b19da46c2d9ec9b81bb7a42632915306f34ba
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:ebbeaf85ba0b407ee56d0d9cc7542335f557a60029ca550a221c6f49857978fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:6f0d5c289626f6a30764972c51c060c3ebba2e31808eea169b5f59c71b2760ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:50eb9d2f4702ed193114be7539e9e49192d40af0a740d224eb4e923c0610ff42
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:80a613dd110f56b2826479cb7a453e014a753fbccce1f27845a499e22b935854
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:9d84a81d08a0fcc9668b46cb8c503651931839e4de7bb0c826f2adb53f38664b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:9344121be6cc9e37e31b23e895da60fa0ee122c5ada2008d27e842a1c361e27e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:644cbadfa6e0f5a05598c326fc9810056f9dfb398c7e05f27f099af1fe410a03