Sign inSign up
Crane

dhi.io/crane

Crane 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.22-alpine3.23-fips-dev, 0.22.1-alpine3.23-fips-dev

Index digest:

sha256:a9b497ee534f950dc9952f05fa2ae7a11662261f3f117f63102d8aefc8d821ee

Manifest digest:

sha256:a30c88a43af7608cd82df01c5eb143ae4d0b34ee556afad8f9b7ee2db9ce87f8

Size

8.70 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:2093a76ecc77cdd6859c5105caa28ef29105f15cc88ca323b67c37362b41b7b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:ce979a9b191db35281ef72b9cdc8a6c70aac10d452d22977079c73c5db3f4654
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crane@sha256:bcff2e06ad8cd68918d78dbb4fbfc0f7d5dbcb757effd1da3212e8ee70d01795
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:edd9327edb64cd85fa479a9aefc7d1d9ade34889c167b3ec02b98a2e8e2eb669
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crane@sha256:3ea9b7164b542fe4b8fd75657f6cfa535b5ce390bf223f9c30085024de8a6a0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:04669a1dc4b3ade818645bda8d50a277a5cc12883c38ee90d89d80adf04a7336
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:96deb2a9260961531b472e525ca60c70358020c83346dc72da4bff653b54fcb9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:6e6b36618a0e0515993f0346aae3a1f5a8d17185a8589a424205c23857ef0b26
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:f66b11da88598cea37b172f5ce0737b3c8f9b179d4c5ad0518b5a52d1ccd01ef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:7410d4614620497e361e967075d99c27a4ddf00f6ddd1c836e7e61c2d6c20a65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:ebd71394c2459bbbb9c45952c6635872757dd65ecd607fb43b1dcafd519bbd7b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:c849c5455187fc69bc2f6c73d1a74b6c58d3dab0c93b38b8ef45266ea1823c35
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:fca49987085b6f2bd9797dde5f7ea5fdf1dbea6c205cd446869d7f0d9392a11e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:0658c4b8d7605f45316e732e62c98c6bf69ebd766e8387d4c5310fd143356390
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:1543fd9be0c7199c7975bb89ca271ed2d6303c2f9313f3fab9d4d40718d2a188
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:ed5795f13242acdd72ef0904e3dc1f2659b36231be4dfc71399f845d8c3dc952
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:fe7b2c138a9167efa97b8abee9f9696f600bfa4b3d620db0fa20d6adb0528079