Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.13-debian-fips-dev, 1.20.13-debian13-fips-dev, 1.20.13-fips-dev

Index digest:

sha256:ff03fa6409214ff51c6eefe15ccf85d4821779236c6f7dfa2e80f3db17b77a55

Manifest digest:

sha256:df674be7ed43d549d93b06f69c74058a396d064371de5785e0f2c87c8bb7bd36

Size

60.93 MB

Last pushed

2 days ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:1850c9a45be64d6e16b58d5461a321f5b0831a4769101ed86d9d246361e79557
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:5541f425351d79350843bf9bf236c372a43dc5edf8f3398cafdf1d4f3dfcc5c6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:c22aa08cc2b2c09adee417457d47ff13d56c057971e0533931500e91c061f4fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:32ed919b951392581797ad898b9467b2d515e7a96d4889882ad7bef06c283535
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:5a36ec92213d0a74b6cacf0b4323fee0bfeb7f4c23cd62607dd6d7b2f178351d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:1129694ec2f7578b6accfca598132768fc5e1cd511f0d70ffdfd76b18046034d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:6501f8656c8354fdeb94ecdf080d54889d4a6874c56a679db3e73b86d66bc792
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:4cef2df67a58b7a9ab15bd0580b1aef818de5f741d5419325a0551ed5167c472
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:50d5482864971f333d3fcf08100c383b15b2ffa44701bf7b1da806f95e762b81
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:4f2413c9f7a35a13646df313d1b30d53e1fcdb959a82539ffbe41dde2e6e5960
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:35a79fca625da2fc9d33586d4949ed511b94e21579e3ddd4933f6951f7206a50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:8f0ea7f1c1e0f4e692164b4a21face2476a79ccce0bcc924baeca3eb91ab6515
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:f92e177f1b6f04c81675ca474026fb152b61fc4c778605e954923163b1842ad7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:4caf87bfd2ea2d04185233703075ae44a611e0e75b4587a498d76a731b7d1c94
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:659d15ae0c555e3c3d9b358df017224381a1a146fc20bf14de15de28390e08c5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:35ff6bfb9c2cba3d08e3d4633ee68b25484fd0ce537b35b6e0e946f0eebe72bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:8d07074b7665c197dcca273ff462225e460406cd054e368c2af9ca55afb20ab8