Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.5-debian-dev, 2.2.5-debian13-dev, 2.2.5-dev

Index digest:

sha256:1bb17a0b33d44fee28405e34e347f7295c56589046ad4dcc16d2fe71a1b29acf

Manifest digest:

sha256:1b4f8534a30c49152161764c7f3bc6eed5b3827c7ad45c9fc8cc182400f58b24

Size

59.36 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:1061584aa9b5bb15e63983a54399a2dae69b45a1fd02c90c19a975fab38af9ff
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:7de0e24dbdb9ca680d760fc04cff40ab4d675cfb7c6cfa7a490304db4258520f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:cf7ec2391c51b6abca53c1716d8e6233d83098405d0f3c3ee2bf92d042204117
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:7431c468c9d3eac2410c0b1cf4714ce3ca9417771960b44f18a6a5df7b38bc65
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:59ebc509f5379a896ed9466b5b01a7c47f48799928b67940e10798f14e894a22
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:cdffdfeaa623d70adb2c80656c07d21b6039f80c0d36f3eaaa3d9cbf5bde2d6f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:9e7037e76be1384f3d427414d6e049d0a2402c51b58af1ba3dbac46383789dc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:71d7f35dff57aa9d90d4597575b635538378bee6d7cf7558c5be823357c674af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:6b0f9aff6f1f2fc451fa913e403ac6c135b10e02a0fd8c90f681610fa426114a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:358fdf895f310bd0d6f07efff0b8e26b5135940a2f1351555575e607f539083d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:4ba9aa07ea3906ec77a7f95c217822402f79c83ccf052e1125497e4c6b7843cd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:329cb0463bc44ddbddb4770d2e71b866d6f85b1e914b51fb155df0e8f0a15799
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:b3c0dd0e997d99a87c3d4751e7a333ac4d983aa732804e18db79d5228e325f36
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:ca24fed2471d5a1ac3cdd9de734c13640a563c7b41a40e1619b4b7e2dfd2bd76
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:0ebe0ba3575e32631c0537cc4989357d6cd36fdc915f13f9493c2cd0cb24fced