Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.12-debian-fips-dev, 1.20.12-debian13-fips-dev, 1.20.12-fips-dev

Index digest:

sha256:1af2798b8f2756ef90419e782b8bd164582b142d24a2c62bfc5f3afe3ef80a33

Manifest digest:

sha256:0725164d6c99c0b78e83cca9ec9f94a1dc55ae12c1e5f15555956bc7a766e475

Size

60.91 MB

Last pushed

4 hours ago

Vulnerabilities

1
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:2a2465aab3eac2e0f2beab2e793ef6326bc1c18eaa7013e1cb10ad7c55c28f29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:77a8493d91536743116dcd72808ea071dd9762cd5c886fc65bbff5be09b30ec2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:3518afeff1580f9f65a2c06906df98b9bae664c22d3599c2051edeb1a383dfca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:de21b32a92ede258da8b3981cde75826cdd59c17bae32dda5a75567c9844a5eb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:5faae85b46c41d18f7d9901026954968f323e4cd7bc143518c40e7ff0baac8fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:9dc12e5848a5f92f675dd382a445acbb36df2acc197f094c9744c825d6cd606a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:67bf7868d1404d64b5c131612e457ad6ac4b554343d59c317dd2b3a1c091853f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:117a8f33aef6c16b65c8f89ee3543b97444fd7b96aff959f280c82de9661a40b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:acce15c0032225203b1bef17823bfd123290f91fbddf5d51a0f995272420fef2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:97b5c95fd3a2811e1fd40500dfa199b308354833994b40d8cb1472555b5eeae4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:6b56a39ac9358c10a9d1686bec7f24e96f3679c82c0ad28e19d2ac3d6b9d9faa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:e96348b083d6d234dd2eb93baacb002864a76e3e4a9c8a6d26bff83e209c99d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:8e81400fbee93527f397931e901397f49959c11ab9ad92b44842d392b55400e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:ef81f4f9cfdb3979402e6bd9c8e7ba3182e0e1ae6b7ffe4169966bb489715cb5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:e801831c5b4d2bb11816ec97e872a8361473ea5da925054aa4a99eb51a1ec784
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:3d454fbd985a10abf64ba8dd29c71cc26d40d1123a6f8b6d8caf97c878777fe4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:bdfc3266ad8dc4b053bef9ec87cc7f21e1a2f398e6b225b3bee695dce8cba575