Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x

CIS
linux/amd64
debian 13
Tags:

2.0, 2.0-debian, 2.0-debian13, 2.0.8, 2.0.8-debian, 2.0.8-debian13

Index digest:

sha256:e7a9260a9e3855f8ff893e01509c0585a8b21e21fabada96aec4a9643e495e29

Manifest digest:

sha256:6aa4f7df81af1c4a1b28a5a0db80d2ef56ddd70596da1a5d3b75666199cd35d8

Size

26.62 MB

Last pushed

4 hours ago

Vulnerabilities

1
1
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:4672d62b79354f6c4fc3089993a3a8fc499bd3ed8170b25fc9bbe3820241ca46
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:c780ebca2f0c653975e6a38190cbbc95a9033152141cd6096e9d432a8a3fbfc6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:abd5676575355576b876fd452b15e568424519d5a87d8f14cda276ae883f657c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:d66431557dd45839a3e922cf75fe74495fd58d112caa80da5b0d52ce859b28d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:385676fadc1ee27c8e0299f95b071a20ac2f31820beec178926f70f31c49e8f8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:44b1d363818646e2ee7db7b53d6d57c52fec492e90d6a1aecd81e52265676999
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:531439b3cc079c2808c27dfae7b65e07e8e9314ee86783e87f993ccdf3fec5fb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:dd06032618d3f689ac2606afa8c0479f251a61ef0ca15bcd74848dbbe08d7c7f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:9e8989441be5af33254d887574d2f5a7f1418be893ff9b01c45e2eaaa3f082ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:903e8799141eb04f0b4bd4ce47c866c47e43e179078505c66c0a84c516212de3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:108998a717d703b990c3c22af53704dd7fff543a1867bb0279553bdae5fbd820
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:bdbaa8709a0914fffbdc1e4e90491f61ac761ceaa39365ee273b3e51feb2607c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:77263852000fdd4ab9f263d710a20d071059b97c7c3e4e582dc98831994c2621
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:1c8d0ec590424d0f48a39243abbd42c0b479b16862625b5c471025bd09272b4a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:1fe3a0a62cb8781bca8cdc724c2bff17409e6e570e7dd75d7b4eed8b30b12ad7