Sign inSign up
Crane

dhi.io/crane

Crane 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.21-debian-fips, 0.21-debian13-fips, 0.21-fips, 0.21.9-debian-fips, 0.21.9-debian13-fips, 0.21.9-fips

Index digest:

sha256:010244bb53776d293e19f16316c61988079d780c9537967e0e9ca3ddbc1247d0

Manifest digest:

sha256:7e4e3ef39295f5b6bee8ec642531c16bf4eb6f4e0004b10360d1240b7366a4ae

Size

12.95 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:3396e4642948e4791869bd0dc4b5afb25330cca153e0e6a393eb4b53b4d60f3b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:1a8c333b5dbec7aced6e9964b0ffd4b3df63b22564c887defc1fe34e7b1b4f91
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crane@sha256:bc4e81099b26d91db96e885bb009b4ec61f548d480355b2da7d4f5bf6f0f95db
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:c4b03e5ecbfbf2a0fd570d1dd47444b4534d4d3fb5ac010f60705a2b80c291bb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crane@sha256:34879c735dea707ff7a94d2d324e2a0928b89dff8a31457875a7a51c26072b99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:9db62e65f0663f39b658d273c33c92ebe94be2214a78619c1fa5b3e4fb912886
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:9707c46d8a6fc016ce9617e738f608c760c7bf651216da959baa502172614662
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:33c6387fe56a097a437d37a1674698e122510275a68c87775ccd8dbf028bfb69
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:0457d86201904585b6c85fc66bdaf92740893df8ef78f25ef2de493dea27199a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:4bee4e7b311a61aaf08de8d1e890e0f6ffc977263b0d7d85f26e825bdfd4577c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:b8ca0083d3ed9764a9e7006315f8ed4d41573dd1f6abc5b2ef79496810c594c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:9e6e96501716889337b4a14bf3067e37262b1f85a24924d144c72735de8e0a70
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:b69fe7cbeb2eb826592869484e6ef1679080133cb399e19729e9d46750d1b455
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:68e57fa83991b8c5137ecc1744c28742c0e33f32a6ed34ae3f62de662757a5ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:1ce35a4e176c51f422d4c7e4af3f081eee3b0a3e15a59d76ce062621d4ce18ce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:977941b0618e305fcf8c6ecf6ae875a7bb389853081a3fb9637b1f56aee62e76
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:9d2c77e4f0e6c9df0012dca4554f808d8c511db69c697d0a00fe54fcb186b0c3