Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips-dev, 2.0-debian13-fips-dev, 2.0-fips-dev, 2.0.8-debian-fips-dev, 2.0.8-debian13-fips-dev, 2.0.8-fips-dev

Index digest:

sha256:d1d202cea8350ed7dc11dd88fc9e245c8f60252f2afdee39b0d21458d1850427

Manifest digest:

sha256:09f4c8f7f3fe8006781aae664bdc4cd15c037f4f88b91f3a601ca0853ab50068

Size

60.88 MB

Last pushed

13 hours ago

Vulnerabilities

1
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:ed3980853a3a418ce450d613f6b8e2ca14f3ec2979753ed24ef28a2d7e72c94d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:0bb1bc087e251e6bc763297de9c4953c6ebe9e58605594aac095fe8e110d4409
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:0633d615265bf18ad1e839e3e74cf6927eb2418ccaa023e0b4c63d135e980746
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:d777cc4b8d907e5ca8dad1d168c64f64c976bc1f5720b1198545cbb6e8eb7926
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:2b287305676092c5c1155ca776ef9e72c4cb9ac59b09be5887e353909f61367a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:cdce04065fce35d783b0f4bae334a14825b81bb8db04db9e88b95dbc0a3b0dc1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:22ec56cb68880708476bc9ba88498108e7a7eb20c3b48daa72fe125280074824
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:443636887b8baaaded3487af6d6fd22dc217f94c50a0f5e258a31851cfc7f1dd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:f5be007826499de33de36c1a372136c74e04ed0f8ac56816f4f89efd3795d77e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:b92fac3122404cff45ebcd989385fb74856ffae8a8e794bcd15e824293f20158
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:a55ffc053ed266625d433f963a6af17135fe50de56b3c93c67fd7709a3a0ef4b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:7fa26ac8d49e288b082648557dd15c44f762bad6495ea4f22b52bdf2e73f8951
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:b0a5941a43a0e4796ce907d442e1a00d65d56232c1210a3e40519f6df6ee75d1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:e14f1ee8859243490d7c16162557ceb8a88611976e8684bd1b7e8ad04cea99cf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:6ea09b795234a38d2782d1e742cbe33377ee25b63da8effba747f81fb198e8a8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:36ed9388402ecf229663a3d6cea1e8ce2b36d8e209fee3b27589aac373218aac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:00b8bcb22d00b890d8f34eaf4c82c9d907a976b082813a3a671cba9bec264b1a