Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 1.20.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.13-debian-dev, 1.20.13-debian13-dev, 1.20.13-dev

Index digest:

sha256:82638ebb695ef0c3334ad3168bc69a2413e5c6aa3ce2c69edc0c28b450f332bf

Manifest digest:

sha256:9c9cc0d2a46e6a68f7c7efc5da02acc538f13b31d39790c021bb7b68207aa466

Size

60.19 MB

Last pushed

10 hours ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:5b06081d0420326f74427bb716d43f58422c8b7ace7698fd33f92a204349c9dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:b22babf64a853868577f81c69e4b11916a3b22de96491a69e79e5e36aa3097c7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:43f8a9002a04354d9c3364415d024fbbd9b987b3c273c16ef944fdd99db06580
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:f457404af436af4ec321ed0a57b433a830627b2a90a32d8811a4001bf446fce5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:47706e81227333ac03c305889df11a03ab00dbe998222db01acd676997323ef2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:cc382c59e8bf6133824dba89469773e949ae49fe698062901f625c65fca5593f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:63720ee2a8dc333819b8d1741c2284ebf9c578f2034f7e97d8f70534ed602035
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:3b883cb2aacf2eff5d1b08f40f90c101ddd303bd9dcd896dc285ccc98b3b8bf7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:7af5300ca78afd956a8e8e92b6c4393142de6cbc620acbc6fec3c354580a477f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:67f299e80793222047b2304d2cba6809638840b7145c4c8b494c343609b35125
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:9bff99f94c6b057b4e9f0c8b06fcd5adc369ae0c729a33e616c33f2e64b292fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:506991d3dd232d7015506d4f9eca0f5e934e90a158eff00201925968c5bc4f6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:1faab0fef3889177c2b68caf6dd3e72d715183cb10037a48b764525553e63b62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:c12e5b613b5fd5f678614314865026ba8fb0479a47092b8ab5648b25a4399c28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:e07c9b9beeaca08c29b5e61765f00b8dd77e7cefd570379cb0607b691fc067a8