Sign inSign up
Crane

dhi.io/crane

Crane 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.22-alpine-dev, 0.22-alpine3.24-dev, 0.22.1-alpine-dev, 0.22.1-alpine3.24-dev

Index digest:

sha256:269e0a9b26a349795d45e3a35f9f399d96f2d4a4d7924410a3ed586771fa961e

Manifest digest:

sha256:2fbe8ba15cd60ac5bb84e9917b0ff068c2bc2b609ef7929ce49201c21ed188d6

Size

7.85 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:730eae5b45e7d8bd2b351aa6f6e20c057f104868ad8dddc5f98beeae38486de0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:6f05556fb99bc19bb1eb86d92fafdc6715d04709a6257a33d95475c1d44cb76a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:364d97a450546eccaf96d36f654a9602192e1bf643f7fcdc40b72742606e1153
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:a5826ad09fc6c7b284ee7be921a36a2d5fb12115a3a91803f6be2d56688638e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:1ab31036e0649bd6e5fd5aa26fedfe68284e4211e41ae53d195fa3fd559142af
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:b6f3061e6f8eed892e39e4d966a2944dea8114f6ca796adb89c1ed97b0706c61
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:c091dd5a83b6c7b4e13e6b41dd6d05442568efa9ddfa06e59c156f5dba439277
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:8d88a43b8a065e63623c98da9c03f08718cc51af45fb3437a60636cf29695e01
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:55285d5dc7ff2d2622cf48d66a35bb868186df331dd4256890c0ab8a3e8c87f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:3f0534d42635c70f34d34c2af6f86145d32f2c6f20ba569b0ecd35e596443d2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:e66103bf3ae0fe65c1777434aedc46af03d4b0604c2bb52c2eb7d4876802ceaa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:d1e149f4771ea42c305ea3ce3a338ff42ac9f0083ed22dde91ee728e2a63232e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:e75ad6217f56b6bef6bcbdc090eecfec6234460d362925ccaae40751e3023590
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:a0d8b7f6399b227cb8e5f7edbce0087ca6b8743801ded09f58c0112722ce7cda
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:33f301ec2f45b7ef6f0beb45781077bf74fb2955b5c2eb783f77757dbdb22bb5