Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.3-debian-dev, 2.3-debian13-dev, 2.3-dev, 2.3.5-debian-dev, 2.3.5-debian13-dev, 2.3.5-dev

Index digest:

sha256:f1138aeb1fbca278fdf3c2ea7d8e1cf33dfe4f320b87c37ba926f39413775341

Manifest digest:

sha256:197ca1458d8759a3756da8ff988413656ad9a44429e3405ce360797e4f04e360

Size

59.52 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:a96b356c8bad45d39ed5cbe288b3eaa24046e4223fab4850385a3eac2f8fbee6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:58899cf09b8fafe4bfb48b8b1ec4c9fb744748ae7ea43177551e576131ba2da6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:f6577b73dc0fc23ee589e3659c08f3fac1cde6d983725fddd00df97fa3278c39
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:0a9fd38c9e309aab4490e5c02062bca6e2d2babf4dfa3d599f98e717994ae33a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:503e41d57d4e4510460858cabbb97c1e74d012bbdda311846b592fdf3729d111
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:0a5e6b24af8077b1fd7477b93c8e28b1cdc1f965f17b7b264a5637e2b8e628af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:e975568b7f88bd44e3dd5cb2e94c8954b8e56bcef9a227ed435d136405e7f3a5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:ac11bdf00156bafd12e83b89c29de3ec1b3b2afa40d4639df5ec3a30f4b24d26
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:8955f3b2998fa1631caa8f78e18b101953ceb395bd539644769a7db6d1beda5b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:eea4525bd9086b017be4d711d9af8d8fca50a018d9345fe7fb1d15767ac07c34
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:5fd4e08d309eaeaef70a20debde2ef1f49541017e92b8b59ac6f3ddc360c3318
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:f735c4bb713fab030e251826d07ddbe6e00068eba961b16592e18f24f0ede182
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:29c44482fd6b8cfe574edba85f39846bc1e928db674a5bd109126db32000135f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:77eee76130065f08da9b4d197ef9cb6f73c3e6f31c1e431e93d6b2703347a991
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:88f2b0e2bd5e6b30fa4c8c0b85b027a3d8e754f73c4d0e3d556fe3d995f0e8a8