Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.1-debian-dev, 2.1-debian13-dev, 2.1-dev, 2.1.8-debian-dev, 2.1.8-debian13-dev, 2.1.8-dev

Index digest:

sha256:c392d23f2760c4704ca1e460894e2b56d694e85c6761aac928b9aa0ed577bfc0

Manifest digest:

sha256:25d59045f4c229c3dfee42df17bb2cf7db509f71d280fe5a452049a395436651

Size

60.25 MB

Last pushed

19 hours ago

Vulnerabilities

1
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:ee005710773ed138e922cc7ef545f8d21c5f7f61cce3cfac6cfc7af1d303a9f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:227145f5f53f2db8de527aa93f7b8993ddb934faa1ee780a2807d30ca86a90bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:aa886cecd449ff494779a56be8a75c75ff29f43d5a6a600872872758ae5dd4ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:950d677cdb069b391bb1f1bb0fd9dc072b164fc7705465249b398099ec6441fd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:9e93f6a85829d2f450b3b81bd1ebde12623ccaff20b964aa968723a0d1e812fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:f603d20f084a01d08bfe62e0b53ce9ecce66161ef20973dc2399dd63ad89b9d2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:6d31dccf90ff99e95637e3f231524306c34d8d7f88ffa7aa6ad6dd0daa3f6f30
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:9fbb0556ccc81fe4246817e8080fe0b6c7f84f839f49f34ddc8b94233e35cccc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:9239fda7935ab7e1c5b311fdd591e18f94261f9fc7e59dafe6f56656a71ed879
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:2e8dd5d3467dfdc7124579a9b6ab8a27dfa9d0cde879bab34fdef2dc932263ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:7780d5098cb950dd5c087ca0426c7bbdf9991bcc0528fcfce0b017231e31f59a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:44ecb0aa32bb5d8e8c610d2b69a363ba52b6dbc5cf002b331b09481d3d1d6d43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:4621a4d4412b31da7d2498c13bdda87f101483cea646e41ed8e9bba8e6f36e9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:045c51e3aff252f6b9cf4f6397680f2e23d12caf939776c242723a90a3138374
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:d860cb3c0e37a0b676a47b403063cfe4ce4c75058365aaa9dced256c83f47a68