Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.4, 2.4-debian, 2.4-debian13, 2.4.0, 2.4.0-debian, 2.4.0-debian13

Index digest:

sha256:395a74a4bded9f58ab14a01fd0ffe0503410c1e3c11399f005bd6b69189b169a

Manifest digest:

sha256:e67b474e88c898cb5d7d4fb34f9f656df2d9a122cbb949e35bc5ab70e89be6d1

Size

26.36 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:f4f051b63d423a5ab968ac41afc7cb72cdbb4562470271cfb3c0978801dc2c17
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:c20c14e2fa34c2fef3db5997dbd80c914acd5adad1242f6347febc5134b9f94d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:c2c91d1ba46a47757d9cf9643a042f756cc52b027930d83b9dfd466c22fa9e89
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:9d2398579fdbbdc688b8ab768339d632638814f52849a379c30c4e19cfed9ccb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:09a422ec6c619daed228eddb09788d2437090399cf6f2afe71bbd73cd61dbb03
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:b01b6718e747ac455180a7cd7e602da31b077bc08aa80aecfdad915c92a83d7a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:1e46cb573adf326af94c613dd3f3a4bd5fe64da922e78ac1ec8d060f4b4fbca1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:221ddb3ed63ba186904cc192b32121c789d45f0700d7ad5c8865cd685df896b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:6a01f7602683c8f3a272f60e469ccd58e8b6e73bc9cc8c346c68707b73bb4ae9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:4ac6a8950a46458b7998b51de42452ef7f455db203d4128dd9718f2590a9018c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:27d382e3b420b0959ba67dcba0858262abb72409daf6b02d84ab5b4ed233d586
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:403a802ddf1260169b5866338d4abbf5060d6e08a0c38b3233bc9a45738da36a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:44796baa7f9589d49db667fe60c3873eb2fa08e6814adcb48dd99ff182b382bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:5090f0215b499401a0593e4510242434f8d621f6c6609da7324b3c27ae6b9913
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:1498fa1ce2b98dce840f376d6d2ad005318969d666e9ffc922f4337b8ea60eed