Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.8-debian-fips-dev, 2.1.8-debian13-fips-dev, 2.1.8-fips-dev

Index digest:

sha256:495271a51b9e5b4b2882ed35855c4954bf2b7f3bfdc9b8ed4e6e72add372d57a

Manifest digest:

sha256:d7cb1def141ea72d7eadd7425742414abcea581a1f5a2b7ebc4250954d909476

Size

60.99 MB

Last pushed

19 hours ago

Vulnerabilities

1
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:966b14be5f3bda81a22df8e576fbbcc24a656b6621538fe1ae642bac9d401386
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:f560af51474cdbb2883a24cd92b80fcb9c310926a0116013844a8e027bcd34be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:34d1d606ba9e2742f5903ab7187c12ccdc85bb0bffcfc799c682c91ccf8e57df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:c3f66133ccab9f8b722d3b625271424432460775ce2bdfa7a81084bf9e4971c8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:1079487661f6057b26272af78471b8ad1d9b1d428da3c8f7473e502e4d251f72
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:1362e285901f558a6af6b372edde9c95532bd27d21cc6c254393517cdc3c9d27
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:17fdde5e5ce93ada31dbf83d3cf536a6d9dcf17bda36db9fc3e113d69d07c2c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:7ed86033a19dbf1158360570a0829da4a8f339572cfc0546e568afbf7d077af8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:13ca27d80a07c404754916334c80cc2bbac8794904669a536a00c91929028c78
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:8bb68f0186e5329d63a311adeb78fcf97710e45fab95f98a7f7072c86d3d59cc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:b86f5f8e06da5e92d067879fc5668ac02fbfdda8de9a7ab89994dcfe0368074a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:6bda80fa616ed13f4d7cb0f15da11ba99ca235a6205fef02f112f26d2397be1f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:c0a79645302d287aaf7772ef0be90758ffccd08d22e98de09ed2b65d41384c1f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:c5cfdc4dcc93c58d7f1844872da49cc640fd4100987178542e1c00e1961da65d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:0dcdaedd1422dc82f5826ff8012b6a482155a6e40c934a86183e7b4e9449aa69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:b99b3805d69371867a57de41a23040d62b12d7ceec8fb669602a94bd8cf2d61c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:536fcfd2eb22fa24b85a0280f8b398f41a9a26706ea63900dbb18d75e33de971