Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.4-debian-dev, 2.4-debian13-dev, 2.4-dev, 2.4.1-debian-dev, 2.4.1-debian13-dev, 2.4.1-dev

Index digest:

sha256:b9998748bd96ef74849f11bd2d7a3b459b92dac525b00417c06b970b66bafb34

Manifest digest:

sha256:dc2c5e77ca1d2680cfd98737687d4205bfa03db95699046e09b0b9ebfdfa39fd

Size

59.63 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:d7bd6dbbab5b3135ca3270d744e5183b97b3f6e6fb06614bd8d4a31b0ba05994
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:34f2333049341c090504a00e5ce660b61a3e35cd23b85b4911190a41c15f69e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:1af6433b3561e80b38eb9694b0c9940b529eea261a53ac63509af6d3a4c878a0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:c2180afa9d12210d2e8cbed866fa9166b14320257ab4f9927c490d02d10c041f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:9aa7ce6ea95993eaeaac7a76877133c60bd6abe9fbe3576b4725a36f8336d67d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:abf491271794117ab556eeb4461bf248d4ef9363d579392a89fb2f54a2e6c9d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:101041d44a276da370500f80710a410c7effa9eba62fd0f31348a4331ac0bd18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:b4d8b3e67b32eb6ffda347a770806a49c3282275c0961b5a7844762a22cbe4ee
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:5296dc073793f05915f24b6a5f010c9e96b007161c32185482755136d232ca1b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:17842e68295e2f96c6f6fb0fc564f9ccf777112ac04845f2b7b14568e8d714cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:9d1a22bef454e875c2a1f66cf96e3470731ae4f2663b889651cf83da0991e54d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:0bec9633cc19b413d012872bdba9d1e1830758c5e10e4f2c41e9217cd4df8be6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:01c5f03d5bf5d714948ae9deae2f3621345f2a673ecb72d9b884320329a25df1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:5f7da1b18d0bbb1a44a0828f68c5c6f8ad8f4aa1691f80579432b31c3ab05708
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:3c89aeb824d01f82863419d3de66376e176aece44b5cb4b74c30ad7bc2297e98