Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-fips-dev, 2.2-debian13-fips-dev, 2.2-fips-dev, 2.2.5-debian-fips-dev, 2.2.5-debian13-fips-dev, 2.2.5-fips-dev

Index digest:

sha256:0cd05a67c832dbc28937a20b2912f8c53a8f923912732abb28e6774d02cac324

Manifest digest:

sha256:d348fbe3d1abca0cbacdca8c9dd265326275bbc13610b096e538d6e3d1abe889

Size

60.12 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:e9ec05c725731ce3c68a50e824b1a855503f0744e641db0df7ada194b1b60a5c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:61174ab84cc5667c97e1918622e788ea283fcc1e9892ffc45e6ce2cac20cb132
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:e0663ad8bbe971fb492500da6e5ea2b67cfd5d7095aac80772e12a53c0eb8ac5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:add2d07000386b711283688b27a8ff31e2b2ded1640ce47812a68047c4ccfb7e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:15ea630566d4880a9886932f8dd6fc324e3c1dffa1d0bd22a885309ddaa7d895
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:f1235cd74ca0271e262c72dab88637f30cf7c8d22e0be5512c0562d1c3be7987
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:b280447601679ace95be3c0201ddb81dba87a07ed22d24b4f5e819651a49638c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:085c074f2312ca3570695a706b444bd25347fc041380a3d7a0307dd5738c1972
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:908b288edabf4934e9a96a89ef82aebde71f6cc3d9f37949e2b85b3d7d183b04
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:ee005178b717f84ee3ad8404a39cdb8484c9347fc8db288c1ea67b993a26815a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:7593ac15df832794a37c6b7b3cd2a8398d6a58d6790ee43db803c32f25b1f9b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:1bace4400dc72562fe3d680297c1bfffc25f9b20653fb29973df154f12c2e0a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:b31dd6110bd23d8a44cfe70ff9eefec116684941cb3e391d9788d1a7ca53158c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:c9d23d4010f86152c745b80eab7575ecb52ff2aa8ce5f2b5889e8567afe8f810
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:e74e3b245e864d04cd6ea2556c7e2354991f8a741248ab9adc974060e6d4ce92
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:f7f862e528d38edc12af1c13623942ba1c955a1eb2ab19bea4207a8a875c2386
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:f1dc7eb5f4b2b38728bacd786f7fd5b56ec22f1fc6ad45dd61b265d6d5142c5c