Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.4-debian-dev, 2.4-debian13-dev, 2.4-dev, 2.4.2-debian-dev, 2.4.2-debian13-dev, 2.4.2-dev

Index digest:

sha256:5b0a35c3bab086b42cbb941acd787b85f012e0ccb10f06f915d67e52496a869c

Manifest digest:

sha256:fa4c65e9cb0692c21ed07fa8efb3417e908ab2d4082f02716297d5a9775b3ade

Size

59.62 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:4906f2385159ac32ad08cef16b94c01dfad9ac682cfce171d02aeb98651c4248
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:0ce47528a18b2b65407a3a7bf437ba11fa1e2ecaa70e47acc1cfed7cd46fa432
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:ab7672cc74b311807b7284fc760a0c828d50dd6fe5dc48651b699267a78ec446
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:353c77eec7a8bc3ec5ab7894452af26d3963979b4f04bf1fe4efb368a4e1b634
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:4599d3153cbba7d3eb297ce0b491533fdbddd91d83aad6d46d90e7c57bf5cf4e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:df7ba1b250dc81112d3be2e5d0254906dbfb95b04289f126d2f87b46dc012f62
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:1f9007efeec8bf77abeb203506417f041f9ebc7e29a1b548a1dd24129dbaed24
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:8fa5dbdb60b04376dc31217da8c61dd6cdfb28571e37cdaead5201248c2e168d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:f90494bc3b5106fbf6d2d50b15b8cd5fc975588f5d3b6ced541b83035a951ad1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:e100f789417df0f9326eaa197fa8d5c394a125fdbe4b7a23f3ec58e64573e666
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:7bc1970aeb2ff8d4240a736c1a218ed98063c44a03405899b0506cb31bc5f6ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:8b1ff6abba908665078a1f249b60d59908cc234cbc8a75c3923ac303f2c11e99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:3507d1117b18520ef195bb35f918df2345afb700403978f114ebd854b5f9c0fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:0448e833301b5f1bdb4eee72c52237ded4461ec277a740d4ab55df11febb72d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:45ab8f20d084541c1c5d0f677fc3b5aa391fd37dfa216feee5e5e28b7d84b26f