dhi.io/crane
0-alpine3.23-fips-dev, 0.22-alpine3.23-fips-dev, 0.22.1-alpine3.23-fips-dev
sha256:a9b497ee534f950dc9952f05fa2ae7a11662261f3f117f63102d8aefc8d821ee
Manifest digest:sha256:a30c88a43af7608cd82df01c5eb143ae4d0b34ee556afad8f9b7ee2db9ce87f8
Size
8.70 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crane:0-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crane:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crane@sha256:2093a76ecc77cdd6859c5105caa28ef29105f15cc88ca323b67c37362b41b7b1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crane@sha256:ce979a9b191db35281ef72b9cdc8a6c70aac10d452d22977079c73c5db3f4654 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/crane@sha256:bcff2e06ad8cd68918d78dbb4fbfc0f7d5dbcb757effd1da3212e8ee70d01795 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crane@sha256:edd9327edb64cd85fa479a9aefc7d1d9ade34889c167b3ec02b98a2e8e2eb669 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/crane@sha256:3ea9b7164b542fe4b8fd75657f6cfa535b5ce390bf223f9c30085024de8a6a0e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crane@sha256:04669a1dc4b3ade818645bda8d50a277a5cc12883c38ee90d89d80adf04a7336 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crane@sha256:96deb2a9260961531b472e525ca60c70358020c83346dc72da4bff653b54fcb9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crane@sha256:6e6b36618a0e0515993f0346aae3a1f5a8d17185a8589a424205c23857ef0b26 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crane@sha256:f66b11da88598cea37b172f5ce0737b3c8f9b179d4c5ad0518b5a52d1ccd01ef |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crane@sha256:7410d4614620497e361e967075d99c27a4ddf00f6ddd1c836e7e61c2d6c20a65 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crane@sha256:ebd71394c2459bbbb9c45952c6635872757dd65ecd607fb43b1dcafd519bbd7b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crane@sha256:c849c5455187fc69bc2f6c73d1a74b6c58d3dab0c93b38b8ef45266ea1823c35 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crane@sha256:fca49987085b6f2bd9797dde5f7ea5fdf1dbea6c205cd446869d7f0d9392a11e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crane@sha256:0658c4b8d7605f45316e732e62c98c6bf69ebd766e8387d4c5310fd143356390 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crane@sha256:1543fd9be0c7199c7975bb89ca271ed2d6303c2f9313f3fab9d4d40718d2a188 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crane@sha256:ed5795f13242acdd72ef0904e3dc1f2659b36231be4dfc71399f845d8c3dc952 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crane@sha256:fe7b2c138a9167efa97b8abee9f9696f600bfa4b3d620db0fa20d6adb0528079 |