Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.4, 2.4-debian, 2.4-debian13, 2.4.2, 2.4.2-debian, 2.4.2-debian13

Index digest:

sha256:a2dd95637a5ea5420874482b5db96fa8fe1b9e70e300be74ef293baf90f81402

Manifest digest:

sha256:faa099eeb67a3aceb659bbac59e7ae7e75b9fe4883c7d43fd7b2f5f994fa910b

Size

26.38 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:31bce4ac9a3aad8e48f8b04cd4159431a9880b77b44eec7d089dc3ef321c85de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:94ac4e98600d8272efa3332fd2bc3ca505d85410cbc653144feb9e7cf6e104fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:81e57f2428dacedd32d149a6f8266333d7741fbee18010cb8155b15acb18ec29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:25ca781dea7ce5a15484e6f64f33b525d3b1b1bce4adf125fb95989c3d7977ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:205ec38f4041b12df09e2f0c7dad4eefe8476cf14f03bb082a05bc1ec3085b47
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:edb2c6f789473cb7f6873c0a44b269e4fa623675c8ddacd0440abb1a9051015c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:e0fa8afcdf245c8b5a8ea615ec43fd614006f03d5e5317012530aeb6eb78798d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:a58867c0f237bd31f7623ad93466353199972ab213192256235bb69364222720
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:38928d870800833e5ece23a8d3f733f7067214470a9d0bb4280d8da55845664c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:19fe9f121bce562cfad306d989b3ecf8538b1b99e2ab60753d83b3916b736400
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:96d89b4d4269ffd343377d29170351d678ef243dce54fe9687903c2af1080655
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:40d79426945bbda692c3875eb277e0724a7ccda07ef1d5484c551cdd795d8839
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:053e7011c283eb3b453f3ab15e6a5e6376d8a14dda7211aec9a05e397578372d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:d3380394f80e1186c4042cee33acb71794388874e6c3f0b626c541207c56dbd2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:f4bbc795880afd005e9115d421d8e952d71ce0722d44b497ac447901192bfe35