Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 1.20.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.20, 1.20-debian, 1.20-debian13, 1.20.13, 1.20.13-debian, 1.20.13-debian13

Index digest:

sha256:cb451b897c4012f5db4966085b379bb4c78de41ced7c3a1e909d4637daa361c9

Manifest digest:

sha256:4959ed8f53148b877caf12c5c987bafb5c076353a10d9e37b06dfeaa53f7762a

Size

26.70 MB

Last pushed

3 days ago

Vulnerabilities

1
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:f1a00ed6d318c12c2446393ea53fd454af29029482900b7900abc3c42416d92e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:446b079587d74e92683a616ba213586d1f910f5aa41fe9a077a17e956431ef09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:c1c295fee1af2a7e5276934798f34ba7a6e3749929438d31f93c9fe14f199102
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:ee36998604b972f8cd41aa4d2a9d91bcda0fe3d39f2d07512dbb0a06e7bbeb77
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:c9a8991a2b5409f3b24cfea38ec74e3cc89779c2493affcfe27d8d2c4420a4c5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:8d9443f445b6ed42652c97b655beaa84726c34d873f5d5f97d7bb439e40be049
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:ac87075aba1661fd2c39cd6a64d850673200c0480cb202b6f0f882ed06f3c50f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:7391f4f705b1b715089cd61f1dfe6f1e9ee0ace97c8f8ea95b475184d72f7b14
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:845cc9c12e98ed9d30eb8dc00dafbac0210993ce91d430979e5afda7800ec4ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:03146d25a3024f10472e12dfdc2792f5277e9eb9b72f5789a501016453578f1f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:ec626b392839149a2d42108d8feb6fff2b9212e61ad211fae0efc86f4d8d1e40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:d98f00752193d4dfac785c2c15778126903c2a1a6dbd4821a2abd69650ead793
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:2a3d7e585f6d82bc33404e6c3c3ea8d516062487f2a98c8111bda4e9f1a610bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:31d8bb947705cfa84271107d7cf49004b4184e074628334767b23bc188e63d9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:13ee15d932d26ff78a79781057fa18977b190b065ecddc312a1cbd8f27752d2c