Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.4, 2.4-debian, 2.4-debian13, 2.4.1, 2.4.1-debian, 2.4.1-debian13

Index digest:

sha256:836361126aaf80acf6009642176804aaf312a37111a2b48c22f62ab0186e6c6b

Manifest digest:

sha256:1305342ecdb82f25c056e49f423030b87f65f7db90843a36125267e1979eac3a

Size

26.36 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:901dd948225f451b0ca08b83dd9f9c0285beeb57a9f8fed27d459beb4fcd5f3e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:3df4c9ee9cc295b51fea61cd9b64d780a500fc94a62a66ee128ffb7822da41d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:a53aa0f3e896908da4dce528eb8132fc245775e331f4b0100010b88019805fbd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:3f5b8453ffb39b191e28efbe9ecec6f65881a520ce8c88b880bee5a2e66d0248
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:f1abb1fd0634bc371169ffd5386b24c064d9cdc7a7a6d3f4a01fa1dd2aff6582
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:ec22e24d212c45a5c8bc5a8e5249e970b607d179d56b08cda0b0242cf29cfc2d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:1a34ea418c9c80a3be8a4b06244913b83a8df2d708357d5fba5eeb2759a08b3b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:fae7dd79f602e454324a7e39fa2044e1ae6e34b8375c6248c8b5f3d16cc78ffd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:a246fe78bc85aec978a4974ffcedf6416bb16d0124fa25b07b8568949caff830
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:0ba02753090c5f44bf122e5f6dcc034ae8799b4d39297924fbd04d52f4f33942
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:cbd866d4113cc03acc5821853b6d9cf88b3bf44b6a95142170a5c4cb812c8c2b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:6867463240b8f2bece72ebd614a9ebadf1577410b291362b34504a16e4636782
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:05c7876c6737f7ef902bd153bcd66a508f9440a1b5fbdf9a16824d450bfd919d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:b55ac6f42d8f6323471ba016e1451ec26faf4d9a29e3e6df0fe0220facfc916e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:df0eae8fe762201e71f148914dff052623801e2def1f88f66d677faa14fdf1a3