dhi.io/crane
0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.22-alpine-fips-dev, 0.22-alpine3.24-fips-dev, 0.22.1-alpine-fips-dev, 0.22.1-alpine3.24-fips-dev
sha256:710ec82fb2899aa54d0a5b50cd3da59b81833079d183f59f849880386292d1f4
Manifest digest:sha256:0082ef2e5e4bdec9a04658b69a908b578dc096437039b55f2d6cba43443725e8
Size
8.71 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crane:0-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crane:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crane@sha256:b2adebdde3dd7a03faad3bb864ec640af830dd1930f153a0b90c2590adf506d4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crane@sha256:db3018a497afb46840a4694af6b19dd730700b0463d83136fda1f710d56db1df |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/crane@sha256:926778c6a62b9cb16b54a1cec8d6910d8812340a1f2ae93b13f65150e327c46a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crane@sha256:b4c137c190fade2749c34cc4b2dae65a48c9bc98498029e156ed9ce0c184bd9c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/crane@sha256:97576336bd91032b2ce5ad55c5d307bf890665200af6c701f844db42e3a6eda3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crane@sha256:571bc0e12f30bd33cb88874449d5dfd6614955fa4db3e29fff35735854c7a82c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crane@sha256:c96cd373eb8d19cad5bb7783f4c2c41a6d372ac488f99e662be8388f249998ce |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crane@sha256:9c55c504565738ba1e367ecd268b43ae5d0da6f7c2059202ad0725fbf2285076 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crane@sha256:98c551050480c7cd63629ecf3cbdbd7c05267290ed58030b30409b554095cca5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crane@sha256:c570318770fa42f0f5719c18ac43d4386cb1ce574152d4bc47e276ca13e10ac0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crane@sha256:4ca126ada20eab92390449aecbb3571c6e3de31b781bffbf43cdcf312841c227 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crane@sha256:b0d571851256143fb3598f2991318cbdbd15460e1e710f9e1d2cb7e1dc7de021 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crane@sha256:5c6bcdd6b943f150906eec81c495ba250d123db325808bc61aa6f676b9555588 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crane@sha256:6ff5578ea1aeff86c7401b0c3854c2d01fdd986ae46e6331c6eb6e1163605a5c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crane@sha256:cc274ae52771d6e4019d41c2bd1a6692402a3c1da36292c1a71463d2aa6b17b1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crane@sha256:bafc0e9f0c50914586762bc765c66466d7209a4517a88a9ed5495feb34b01fdf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crane@sha256:2a8a192f8f8fcee81e8c5ae5ec62e8fef3120e7ad4359a19fae1e827a0670971 |