Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.0-debian-dev, 2.0-debian13-dev, 2.0-dev, 2.0.8-debian-dev, 2.0.8-debian13-dev, 2.0.8-dev

Index digest:

sha256:d600fe1c7ad45aa8dfb7b37a6a600709b44023a5ab2ab7d3818b6c4c901ab0f7

Manifest digest:

sha256:8efe4a32e58faa93049fc027fb9e42611d22d1bb73a62f85ea70aa922f28342b

Size

60.13 MB

Last pushed

1 day ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:5ba4b9c893291e6d640e93d890524749de914b19fc73fa788f60b1810f40ef3e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:d4a07e6ddff37d3b1e99f4ce1d08d2fb9014fa67900a592acebfabda73870957
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:4141a81fcdda6ca44a7a11043bad92e9c9ed88a1f1d43d759577a1721b18da5e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:be4ce3551fd46b53ef5c26c80f43dfa4c494e61f336eec3f52dc880673385122
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:86133f2273d1f3495c9223e4d3044f235593d47e5a907748434513dd3e2d4cad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:be90b6d461999085ff68f43f1c0a8b073642f4e592eb7c34ca30c71d77e5dc3c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:0ff72a8e87963b42ce3175a0ae331c96ca32576e898850b5ef3ec2d070927c3d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:273c4024c987a6a1a230a15771238ae27fe66d08da829250f0fe20c052ac2c89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:450cc24cfbe85da48ca4f919dd0488742acc67ee97613068e127b3f1576f4bf4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:48ee28c9350ed33e696628e06a33e82d47d3b6dd9635bcb6066ca5c713aa2a3f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:665e84910c4050589830f46a1b7eab345a16efa7d4e40cd3edcb4f049e757949
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:929b8374b0170940b1e822646d55d78e43cd626aa970cd1041deda42907cd73e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:a86c7f1889958678d9293e8017493055e46bbcc729a2fad0cbf9326e308283a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:807efdfa3955edad2d3fa660aea4221bbaa10edcc570d942f692a950f0daccda
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:7b98ce5cf3d179e156fbff1786116bb53f4bf5e9fdfae775d1a82e1206d66d7a