Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips-dev, 2.0-debian13-fips-dev, 2.0-fips-dev, 2.0.8-debian-fips-dev, 2.0.8-debian13-fips-dev, 2.0.8-fips-dev

Index digest:

sha256:69d71f1dd68673381a5464a252e8c7c6c24235d71dc7cded727d32d296b4b16a

Manifest digest:

sha256:c8a272488033b4964d3a90898ec1392d4afac8c4a3e8aa3670b3352d2e426472

Size

60.94 MB

Last pushed

1 day ago

Vulnerabilities

1
0
0
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:6d303f97393964da361bf5e9a319fa9216b9b2144f19378aa09a575ca21802bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:2d8af255ccba1bff13bddb660d1a4d661ab375a08d2150bcb03db7c55e452485
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:ae0d2ef78096d85a864cd6a99687c7b531c7ae24404a0dc08147763597cd16f9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:670fe7b69193dcccd3277766819ef815a2aca5f26ff49c0696d964d6a4900006
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:40eda868ebd13c05a8546fec94a0bfa0aa96386b8af6b522d74de61a652eac11
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:cc684dc9fada1b7085a5aff1a0343d7df2703c1b6da85e0f62f43aa84b0888be
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:3f3e97a099010c2ff4af0a0153ac1d0799152ddc8f87a0fea34c94694c28ecf0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:c97d7ce0ce66d3e66d21f1408aa62ad1da04bfa250de77356f3ac324c7d5d6ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:1ed65f4d62953438556de25d792b1bfdadf54df385c4171af9208cd70bdfd379
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:ac07d02e79c8cd02883c446ca606bf2e7f1e3ed49c565065b99e472515ae7886
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:299d5f34dc49de63cb7eea010be423b38592300609819039fca3cacd99325e72
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:b78855833630564a53aad1e32f312509474dc3eff5e6dc8d91dca08a164a665c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:a0c87e9388200555f843ef3fe31cfb86d4a9a6e15aa0fedf8de816c093865e9b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:f832d07f701603bcf722ca6dbf2727c09e8394ff11b40caa91af30de826a561f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:8c587428be4447c165c9df71a5bc9dc7ce79c2a59f410212ad26a05247ced488
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:5b605dbe00bca6804c4e9c6cf429ed9e1087c7cb4142f63f0530f59153247441
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:615b046c3023fec66d9f96eb9c7ed6b7b40106e5c3ca725b6130bc9fbdbeb77d