Sign inSign up
Crane

dhi.io/crane

Crane 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.21-debian-fips-dev, 0.21-debian13-fips-dev, 0.21-fips-dev, 0.21.9-debian-fips-dev, 0.21.9-debian13-fips-dev, 0.21.9-fips-dev

Index digest:

sha256:0074e54ac3f22956068ea115a23d6cc3f4fa201a04691ac44b0b3de2deda7b04

Manifest digest:

sha256:7750e6d96655d0a7b7735553cd2be44f371d8605a34e55d6d74743a34c08cdfc

Size

28.10 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:746d64a935fa6bf04e1c51708d011113cb3bb16126df51df93c836a942d4327c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:02cc2e4f880922a827dce9128073eeaf5392b67bdd4adb4104dfe6b9d0ca1bca
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crane@sha256:ed29be08bb006fc3901f9d76d8f5f4ae9c4653daf4114dd08ed493c9e5fc9513
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:cdb547edee2be593d18c1228d9e4921a8ee25348b2a0329c0412559d601c99b1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crane@sha256:90907943af17f5f19a7f409af1224a0f9e9098cd3ba3f6cf20db2398f7cb4181
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:b9db80744dff00bebc36cf745eb0782b72812eaeaeb9d734a42e44e6cbd3e8cb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:8a630179b640bcf840e2773324c1c8be431159175a350eb2332e0840450405e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:924980469cd76c0ecf74a2f8707ddbbe615a7c9b55a701bef3c75584d91f2e6d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:1d40c56939f105bd3ccd25ec084813c49c6eca7b8ed373b2845360d3e1842426
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:b65e203b613e310c2ce4a984559ffeb222bc73e6d1d733914673987d38a849cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:3bd3d697d5b2731fb4ef95b76be4a2777b5e3aa2d1863b3b5fd6c695a34c90ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:1934411d8d1ed7dfff8f5c46a127813564ea2508861e9dcaeb24a4afd4a15ba3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:a23e33b047fd193c49501453dda6f5a25665cedb0acaf76ca25d8b5f4063e080
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:698c30765c45176ac67f19b7b39a106616056df9253895a9987759e90804bd6d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:cadf549bf00603a6c6ddb6127506b5dd39c9eef2b47718746115cffd7dccf606
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:8dac03e9b92bdb0ddd88eb0192d0d86e611bf23cb3e0661b7b2197704add6747
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:c5f82008aad97bdaa42f00c12c9428be358b4ebfb9620aeaeaeeaacf157c1897