Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips-dev, 2.0-debian13-fips-dev, 2.0-fips-dev, 2.0.8-debian-fips-dev, 2.0.8-debian13-fips-dev, 2.0.8-fips-dev

Index digest:

sha256:96940cc9cf94506888f787d00a83307b6e06ba60ef5c2b805602a115f2a7fced

Manifest digest:

sha256:6e186c49ca152b13f60008752cc47df2cca70b5e31f26a5f520f8b772f008395

Size

60.90 MB

Last pushed

3 days ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:371e021eb93f7052b8d995c19e03bdb79d326cb7a126a89efa8f27afaa7f1be7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:25b63ce3718222f1ae5b09cc2aa52efd9f90b37dc1e56174aeedc07a374e8347
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:f8ec75dd8c5481956c6e0aef746852a44367f37e96aa74f377633e2dcbe197dc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:54e91b1372ef10afbc0dd6296e3b6badf8a98e1162e0451dea7dabb86a3367e9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:e6d515818942a9613dd9425e823938d29a7e4b572109492602918d54a92db192
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:6e5ea4d29116065eec87e14e4e45fc34c5cec275ba55df687d14e747b7bf6f12
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:c30470d6d016d90b703d5140f713bb3165ceccde6115267fce3231aebc930d7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:f9c3cc7f315246910a785ec4c406ebf93f8102757d95f9e77a84a38c52b8b597
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:9df21c38f50e36094e2e0cc5a5decbedb6625dc935bd5cb842aa8e1d7deca269
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:563dad29108c7f959751f13d63db85f3e5740528669b9030185844030d26e417
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:3e14737305c0494659edb7a00d08f7f591ed3ccf70d7a7b91b1523fefb005f0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:5e6f9a6349841e53af881dbb4a28e017556e72a732aaf2accbbbf62605eb36a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:54c0da2af7a4aaf3cabba33c194f5a142e6595aa5a5116b29e5264d283b572db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:76d7b090210e944becf8bc232f1bea222f66dab6d056ab8521fdd5ca8e83af2d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:dfee3b80f455e2397956e05b2e5539545a0873759ffac870f5a646a0a520a14d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:2cda39e5c95473c5f964991e37b7b733086bd7757a233d5da139dcf4ae833efc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:db71d72ef9789fa2f16c16f72f09f9f0596eecc71ab76fda697d74db5059f312