Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.2-debian-fips-dev, 2.4.2-debian13-fips-dev, 2.4.2-fips-dev

Index digest:

sha256:026d048beb9edce14bc795d4899db5e495af9d91bcd7e185fe3f64f6284fc142

Manifest digest:

sha256:9574da0c88934f9ecf411b3260fa421ade3781f264796c6abaec2624fd6cd600

Size

60.40 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:f5b870f63de3d7c3536c3e4ca633ad14871f45aa0a9a9f768c2e77c2d77aade9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:923d10c570188185c28c11e48bde0ce1139f75e45bef1d7633c04c19edfa055b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:f2353b72ba8e6c678f23ffe98af283477c26d531cb6e45c8788b676bd6655c2c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:d05945e9210cde9d8ba9e60394e78f0f925a28aa55b21cdb6f972945fe6e0e65
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:c538906df85abe0b863739c1f4c4e95d7bd97729db0efaa8e8c6f4f629433a38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:1d127f26d95c12e13ae91e3174b1fc2ee88abf140198a4cdeaa8a9f0e7876897
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:c0e4af891282d29d9dd087cf9829ca23ff3d7fbb51fb600e493303c540b0c290
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:07247c7f51f7813d73afc3a9d99dd73ee459dd92ce5dabdcab2d3cfa5425a78b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:2a7e3a946d3c0240cfbd81cbae539e788f6c94823773bca02751c6c6df541fcb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:c0c5e4229511a4adf63857e6148a8e13e07315de9ee8de1f8f5b173b4eb8aa72
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:1f031e9442d754936a3758fc18a1c857002a063748c03dc07d35fa1a2c233cd0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:4ee365e83757c9ccb368523695cbe4610e2786b3f35b2551c3dc3fc6ab41aa66
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:8a2bb7ac2eff34d19e95fe03f62424bfd380aa23f76aed25bff555d32e595a92
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:0689ca344a96f65dccb71b78368d0abccafd6336fb597e12300d7e59770c1299
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:c6150d29673df5b647d9826f3314eb520aff0980a1c2be3093e17e53406d7021
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:69237ceb3b6cb70e84993276f15400b337453a9e80ca3f73460f262392b6e979
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:ce588ede03432e1c6a133e64308ca7202ec57ae503210bc81cc431e8bd533df2