Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips-dev, 2.0-debian13-fips-dev, 2.0-fips-dev, 2.0.8-debian-fips-dev, 2.0.8-debian13-fips-dev, 2.0.8-fips-dev

Index digest:

sha256:8976b0124960dd1818af6089b15f6a7e045020b3915c9e6695617750df700ab2

Manifest digest:

sha256:98064d76f3611fc1d0a3c28050256e5503f5ab902a5ff4ce29f516accc73af8c

Size

60.89 MB

Last pushed

8 hours ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:187cf7b34b7182db3eb02bffbb05fd04a69551d5903f97a34eb1acd4415a8390
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:0592581d27f4e6e141f514d170b9275caf7edb4d39d653be540ff54a01d12bb3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:95f9a9e1aa75494858d84577a98a24ddfc4762b7efd8ef8ba768cabef0783902
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:fe424cc17ac297fda3a033e0ebce104762ea93fe988bc8249c51c75d0a0c2e15
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:7f9ef23fe64d38b21e7751b8657733c245c0822f0b3fd52de39d58f0e931345c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:01d9ebd3b52380e81e7c5ecac835f5629bed533197de717ab46661aae00f196a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:afeabf55bf2107ae4e4e063a82293fc52265f6b0b67180c58703fcc728e34ea7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:9355a3b8852757a7d6db9818b99d854e9a7eb1b24a3aa03a64948209e5e94d38
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:82448f595b81bdeea4e691ce43e1b39dcb4d8422b69e04eaefa6c08024abed61
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:d89b015f070f203c04984ef045e281b33783c0e825a533355771a872348d5dad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:106aaa77ee096290e66cece44dc1189cd722c50f2df08dfe2a27e97965a8b299
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:00b3aad038f6dda601f6ba62995535f9031209b8f9d9b9911a19c807e3316dc5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:dc756fc8a68edef8d561b54efb18eb49580dbe372e34e46cf78d9b887023df59
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:59977e3e417c5b31791047e5cbb22d0b3834aba22a6cbcde55acef0e3810cb46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:57716e51d8db1e72b1ea92f5064c6445e0e24208b29d76d30d60a7722950505b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:18999798411865894daa83681307ee1fd05a14bda85d55e9270f594d2ee44066
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:3ee01cd76e2737f0caa090274e435f849f3a517df0f8cbe7efd012855534078a