Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.4, 2.4-debian, 2.4-debian13, 2.4.2, 2.4.2-debian, 2.4.2-debian13

Index digest:

sha256:76b5eb4fd7b04ad40c54c2ae5216bf4ab2ecd27ee2d8670d63dd2015aff1c011

Manifest digest:

sha256:08b7ba4e4bbba227db50cb8577db5a101dea595a5daadbca88ae2554711c31f5

Size

26.37 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:4f107ada6fd56e61fa6986111d0faab82284a26df97a8d9b75aa7e22db7b4ac3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:8a5415285539813ea382c11abb205271df675c682350632b95c6a90fddef720f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:00a335f309e2bc257a86e8ffac6bc06797351c55135be0cd5251c5f312e7d466
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:a6d8e002b5c3e0326e5a3a2a4123d08b0f8f7316a1650f76802c249e91bfdcb8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:889eda1e2d40f916a660b20a50118460df264bc3d3e426bd2bf8f5ff9337e0e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:b93f529e01c1cf1e1ca28a9aa9e13a6a93ec9675eb244077c30a7cdd2a973731
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:8fa781922be1d9fa54c20fec0c51d8da8a41dbec7325cb043ca6836ac83271bf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:efdf7868120c6951fd271ff97541f1b61ba1884a05342416ff5fe01d870d3b30
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:da7b8ff449b11c679d66e4ddc864076ebcb6e6f83a2e66e3ccd8a901ac711047
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:3c945f4a7b82af4bb8b97eaabbbed8519423a65d968206b613b6a1c55ad6343e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:dccd011643c898bfbee95adfdf04d9565aa74e536423a112f4c1867bf6dd62d4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:76564527f61232121ef4ed0cea4e53713524ced88c1affd4d3db529dd64098bf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:4019f57f68b68f5f634c3fc6462aaa8aa0e8e7de41604ed30791470c9cbdfa79
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:ec86fbe005c086cae7ca4c6b8944d41e7f673a8de335b02c1992f36b20b241cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:b9e744ccf677d46373c8bdf8aa7c0f7009b49cbd0c6143f00d76d8a4c59ddd3f