Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-fips-dev, 2.2-debian13-fips-dev, 2.2-fips-dev, 2.2.6-debian-fips-dev, 2.2.6-debian13-fips-dev, 2.2.6-fips-dev

Index digest:

sha256:7960823fe4a174d4e71d819603c671ebf4b4cb4162cc16af868a0aecbb47f2be

Manifest digest:

sha256:03fea2292440d3c25a2e4cda435781d260510e2210d88b0b80fa55730dcec911

Size

60.15 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:123155cbb78c712218c0604fd308199c49a288027fdf8044342c3ff3f6457d13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:1500c317cd443a1a9bb5b00ce5b33771b49cb83c6a8a33c33e5c4d4b59386e5e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:20e10d55654f53fd5a5982d23217697d926323885633dc2a6125a80fdf968403
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:29e7c43bdeaac279bf3c93b6f65a6f8ef309a2f58a064f73e41676c41beab88c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:1ebe5d5624cc8c7dc8e576852efaad79ce82868658a3138e162a5933ae5cbf11
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:0f21ae5857c778a30f05ded28cdf5278e003d6106abc99b87267f9eaf0f8e4fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:97af3234685195f6292536f91bb3baa366fe7a9002e1ecf69cd44162af60c0c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:18291f72ddc2b83741768af18313c2110749d4d445de1f3ba9fa5ee30e4d7266
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:290cefe426ba203792253864a36e8c447e6289193114c2b0505c13775dd02287
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:8ba6be2d9f84dd84bc574f78754d98097a0e342811065f3ac08182fe466e72ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:cae2a1b3e5721d9cfab0f691e9baef17d2a1c89622802b4e0d335e3bf66dda55
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:b0fe79aa5b67294d83aac4c31901c8c70258e36b16452acef776aa128d60a74a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:31e6b061d1a720c991f66be87d570c108f51083965fd99098762bf8e91cc6bda
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:90f28cd1bc6421256fc85510cfdbf5838e2a6f9e1382b4bd7f4b6c4801441042
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:7d29770579df822834bc4e4928241e40ca2a3441b66713a48dd39a50b4479e16
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:63bfa7700a1a56794b677e7717d3f0dc35390fcafd337e7d2f806ab5afc87395
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:2853d7b06c85de71ce241781f637854b666f8b46c7d47997efda3bb39e7e6545