Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.3-debian-fips-dev, 2.3-debian13-fips-dev, 2.3-fips-dev, 2.3.6-debian-fips-dev, 2.3.6-debian13-fips-dev, 2.3.6-fips-dev

Index digest:

sha256:5293a2862543ff0a9e4a32a3c1e1153e6258904813fdd23580251d140e443791

Manifest digest:

sha256:859d7a001692c69b6a3e1889faa322c5a77598e868ddb361e788e8489ef527cb

Size

60.33 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:710457a794824153c8ee55ca9551692ee47093b78956c737caaf7bc3e8bef7d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:bf1d19a08e2cdb8602305c5bea656c0eece706a16329a06168ad7f874f1bf141
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:27d3d0c355684aa216d7d35fc7a1e53359bb919a26296507bcb73a7be6f4e3c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:b2f3ee139463933846b3ed8f0d45be92db6d59ec7bb34645f88cc4a2d2369529
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:ca6ffa9e223787c40247cba9b1a69822bf311450d3ab6a54e8761532fe1529ab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:c197f899f344a63c3c203e85c2bef4e4a350e1b4ee8bd12caffc33d98596d4d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:1a6cff1cdd1d789b606ddab62d9be3bf476d4c13391eb9f793792923cd387bfc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:e864744558cecc9154ebbc69c52e3f774571b1df3a57fab45ff218e314a1aab9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:115e44326d9e7523517665bd560a80add2db1b0d5b109e3e1fa679f610e3fbfa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:f17bbcc8878dabd3cd3060a5d1dfbf49742a1170defeb8dae88268968cea52cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:1f43482ca7db68d1a9de3421c7e86b5b2f1c5125e81b70c04d8924fc5fd05efb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:d347e6b8f55cc98d2967c881cdd870a7269fec1105a000abb0839d6a0ffc1770
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:7646c4bb5355af70e8d166dd7388afea4cf21695b51e922c86ec36718f517a2c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:ae849deacd876924126bdbfbbf72a6fadf6354647bc78a57cc123817ba789cd6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:92705fb565ad5911ba01840ea804ac33143e9662e571f0c3c8bdeed35d06d4d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:7d1aced710084201bd6ecf61fe09431e678e7d62a0f15503d9f2320359a3dfbf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:550bac2ad961fbaa983c9b686e44efbb13ae086cc163b05a1af84e506cb1ca46