Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.4-debian-dev, 2.4-debian13-dev, 2.4-dev, 2.4.2-debian-dev, 2.4.2-debian13-dev, 2.4.2-dev

Index digest:

sha256:ccc73abadf4373d5da8e704325d836f68fa96bae0f01896935a9dbc1ad607d8a

Manifest digest:

sha256:ab426e120624c950ff4f69919b44a2d9c2b9192abbd16b0103c896b7d706d84f

Size

59.62 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:40bebadeef8feac5936983a74d740bb88c46ea4db923731b451d149ac94b9d2d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:e592f69719d52ada1394541e4cc301ecd5b4eabae63ee128930b4fa49a7312ee
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:15de25bf4517526d8263fd0bf007d27ea9094821be4ee94ebe57605f49adb0ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:bf3a95e70e749847f43a2a452bd8ad7b3487032feb40fdb7cf56fb45e7a4e3ff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:8dfcd90a1cae5aaacbed4617ae71f88f27c61403d5a67ba148c71f04bb0fe945
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:24abce980cfcb623378dd0ef1bcae3c51a41229044590f62269f7157d1eb448f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:aa0ebf717e660dc1a611ebf199dfd6f48cd140d735bee2c15700e3e2bfd61274
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:5d5806e900bcf10e88aa71dbe096f6f79cbfb995c87c8c7ae68557b17c343ec5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:7446a38b139d39bf93f4e88513d806dcc4a62ce1b3e8a7152138030e77399cd3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:597856d9ec5c12bdc8f5e522ccd8d959f716bdd567b564f675d717c97bc91c39
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:1fa8b31f80bd43876545c76bea7802c5e6500c8d2d6dd27f8c53ff85c2f1ccde
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:ce468af46124f52ee00c3a27a70a12246cb802d222997519cddacb2a7c8e0a8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:d1f9158ac5948e0e293f63316c4d1552138ddea58d930238294271aabe28e861
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:139b78ca754c9d2661f9d0cca33fdad38504e99253c59f323b579931a7030db9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:4874f171a95f90cddbc4cd0fb386b71e2159e7aad1eefc083f70aff3dab115c6