Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.3-debian-fips, 2.3-debian13-fips, 2.3-fips, 2.3.6-debian-fips, 2.3.6-debian13-fips, 2.3.6-fips

Index digest:

sha256:c32c3703b0cc873341350c20033d0d6827e9ac3e428b0f01ba27267c816f23c9

Manifest digest:

sha256:c34acb86392852d15367b0ebc4fa0597ffb88c8e4f36662efee903e8e01e8c68

Size

26.86 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:b1155d0280c9271537e3c7de0d108e0312a3412356c3a63ea5b38ebd98362fd4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:b7b6a7fc6dc015bf4c01b939e4caeee71712b43d082d65e41c3144c2e2638d6c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:fbe987b44431626903335328ecb2d18813d068205e04421dbc50fc86c5eb5361
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:1bbb07c393bc1819d538d63560e879a7079ab80b85362b90641e1bb0b86d2cd5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:4535b02747116d5b060bc5474d27f2156d1fb243c7b926fea3ae912e96c84d31
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:e0726015ba87ce6a457d7ed0ee7317d106c9bae333e1a112e2a8d19abe950c6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:61c7ebdf05b04d664ed5666d03b117b5d6c7dc392d01cdc7fbd6a3ff9d088b21
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:d2c6a049fdb0b9477b5136835db921d878b1dae56666cbea754dd380be39077d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:fafb49db0c19d61337073aecc8a94b658b34c4cef8ce71350ac474bbb2b8aa1b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:b5dd204607946c4f99a18f7d437ea324632904bda69dbdc52036b7191ee9c624
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:b905c89d862087f3ece1212b6966e45519b9bfca5223e821efd0970b148d0006
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:fe2abba1a3c2a47317f7d65da0558103e23efd028f3b19812a8ffeea75608d77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:ea3cf0df3375dd6e13aa2b5a24b086e7d52c34974c0365f1ef6436c01a46c35f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:b5659ab9609b8085f57f6efdda5272187ab23785655a27dedf131207a10a7fe0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:1159fbce2c26cc6db3acbcca61db822bee978686e3551bff3e070993cd718e2b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:dbbced1a99ccd47c1a768285499ce6e96a43d4c8ccb0830203402d7c02f93d7d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:ab83dcac8aa7f9c4b13b98135d9b8b657148769e8a92969856fd96cabf4e1e2a