Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.4, 2.4-debian, 2.4-debian13, 2.4.2, 2.4.2-debian, 2.4.2-debian13

Index digest:

sha256:95175f55fce31470328afe624b1f59351bbf8686081628b3c509e9e617adb927

Manifest digest:

sha256:bb3fcdc4e2aac886252809f642abc135bfb47a07f0f5164e440427d6a216c493

Size

26.37 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:f724d70c620cd5a81b6bd4973b9a313051b7be128474d989dd1ad3e76a22bb0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:a3294da519f57565461ccb1fdf7820e61c3415b34a5cfc4a4820b91595ccf2fd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:bda44cd066fefe05214bda09eaa468dfccc09b7c53e334b61cef15abd4101160
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:70f04b60dffad80e1055c9b0ab32448adf8baed071812940dd565310662428dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:e4abbdaecbc22fa51949864de64574c473e609531c90a3989bd919d7b83825bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:c2505e8743987976d3339fdc9c36ad557685754aa4529aba1bb19879944a2383
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:8e2fe81aa8393873a99fac3579fcabfad4b15079b781b156f401646b637841b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:becc72dd72308a3dbc1f0191e5937b745fbb94d93305891c1d4fcc83dff224bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:c167d818908a2744f0aeffda1c7e3af123e7bac7160de9d11bc610355af0ee0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:e1405304b937efe3e46086021fe82692d16b918a0376d63a13472ed19edb19a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:735f46d3279aa241e1dce5f34a0f0b49988aa64bf025b46088944484b5aee6f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:70b359af214487c5a87eb0441117d22e82c763ceabc8adc0052d8d97814db44f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:df6064ca426b4b88a3a3a3afe1479d615ecd8656725fe7200cff46cd26cfa3c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:58e0a24397eaeb5d11c745b553733760b6976e9fa6bd9bf098d5fabdba73e933
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:5cbcc3f4e1a5fbe0b1729a9cf59961186c36ee3ad3d81a2fc67f07e5452b4844