Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips-dev, 2.0-debian13-fips-dev, 2.0-fips-dev, 2.0.8-debian-fips-dev, 2.0.8-debian13-fips-dev, 2.0.8-fips-dev

Index digest:

sha256:cc2407c1b449a2dee23e5dd02d22fca67ed15747d85a8cc23da4adce14b8d5c3

Manifest digest:

sha256:671c93db0cab94d3cc6640be795d732a52be13df0d86706bf471104bb1dbc330

Size

60.90 MB

Last pushed

2 days ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:8c10c2d9074ec431999f8529acd03484b6fea3f7fd2c6c095af74b76c86efc79
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:675fa91ff61437f23715b91e1de1d14b1192013e377ce0448c8caf272f27942c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:4f8b83a773fe217fbdb4484723e459e9f85d0baea9a7e018bdda8055c94e32d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:19a8503fe2cd52257dd69cf6486777a7fe68e1612433cd9d6c21703aa85df8de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:45dd3cb05ac79d3e8ec1d79b2b4632c30b5e59b97c6293be86b644b063a2896d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:20e8a881dc13358b8555afacbd8ef4f9123728cc91e1de40e328858d82e867b7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:5fff59f4d8c87f842e288f110d62dd587cf75112bddc7db5c76268365ce4a394
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:57717c102ac45ec139d997c890a3d257281ddb57d35a4aa32d808349b8419f19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:0a75502c0d2ebf1cd6bdfe6a42e1c295979fb6c686479f234ebb85ecda2b4958
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:8ac6f345d00e3ea9f2efd87dbfed1e2f92f663f9e2d536f9b46a4772d0ad450f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:f19d234a0a259505a0775618d93885763e8129bf387782fbeb739be822feabfa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:5f55046d02003d280bf29d94c7ad773d8754455d1f540fdbe84dc08923a90061
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:bcab7bb9d105e9126868c1090499ab421b04ce38525fba559ebb1b481449ce27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:559b5c06ffb8491f7fb7929db0fe08fe7f7f40036cace9539d2ab45578eb5b0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:9529cc431da92264b11c4e4adb082a20c6d96be8990109f8f83d43c87735649a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:9b7b2c4fedbb3b81b62ff278311e3983e67120195e45d2ff0986fc112e8c0575
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:808bcf87796e2ad553c651d640e683896f1e2903381cebfc4190b8f205e26eb9