Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips, 2.0-debian13-fips, 2.0-fips, 2.0.8-debian-fips, 2.0.8-debian13-fips, 2.0.8-fips

Index digest:

sha256:878f249b9e5c5694002dd8dd64fb0d743e3845d279c044282e19ce7bb6f92a23

Manifest digest:

sha256:9a0ba43784fa7e156969d99389769dd6d16674f941b5fb61c615f88694272590

Size

27.17 MB

Last pushed

2 hours ago

Vulnerabilities

1
1
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:f98cbe816e968086098c3e3fa83af38454dae36f4f5553dcca2da1613569f27b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:0998c60a4ef84c1f6eb81c1ba1718f38d1e6cf4bbbd97e81af5933828c773f9f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:407a3666f3b40295067cd57f7356b338e7cb4d648f9d5b8c26fe84df87f62616
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:867c1e41d0a1634ec14ff49f4d8a66840ee234079bf5449b70a6c61f29ca4608
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:0f99db3eca3b294fe8158b47275dd22056d54d26606085f90eda462947b498b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:a95a7c3704dce6c6d79c962a768f81b7d45d0600e1c46a20426f3449f44b92f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:dd6cf2c19d9187fe6dfa7fd93ed9e8bef465124edd39885cfeb251494386cd32
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:7cb6f7ecf2f21d123277f8fb95c3d5f6b7704fab77276dffbc92f5f76a4ef03c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:1a889f6b3fdc93b5d63571f32ece19755034c8f815f9830ec50fbc1b20983d5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:849fcce501b9bcc546552dbfc50e3ac18769fb1e67939397fb7c2888618ab8be
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:d72dfe0f2a64a5061f1986760c235f4487e633eb1597b9f225f9705d35e2c4f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:a024f59c54e7f34e5e95a03f40b2e937637b87cab8b44e87e969a2a8c3bacd9d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:a5f1ec5163e9a16211c7a1c1a1e4211d8101981c590cdb6975d3f445b104e465
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:07657e8cc41cfb1f1c0e917867c9905837be5065b540958ed046490ae89e6bda
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:c2ce3e5de82f1c155b8999e3ac835e1585fd5909306b29f8250722f7744c102a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:155da4a666eb016853c7b0717e17e3b58d4659c7a8faab3fe384b9be1bab87b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:5d374c1907bd96a4c0eb4d9ca9f5ec2edac148b666725a6dac329159e1ee5ecf