Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.1-debian-dev, 2.1-debian13-dev, 2.1-dev, 2.1.8-debian-dev, 2.1.8-debian13-dev, 2.1.8-dev

Index digest:

sha256:84bc9fd3124a5aab0a34d835a34a6ebd8d45bee08cf4ca8324e1cc5f5ecfb4b8

Manifest digest:

sha256:4b4a34456830043bad991d0b7ba77f1b61f12251761b38e3fe66a2a7454bf819

Size

60.26 MB

Last pushed

12 hours ago

Vulnerabilities

1
0
0
1
14

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:5a2aa27ff3f4b0e0865eac83a10d1594f7472391c77fab1407fa1813ef4574c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:c31cb20e16c449f220dec08e2beeaa547e387cba75877780a46c8e63227522ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:2e3d302961a0bfec024c2457b9e8547771138b5e943c8f622e491ded8219695a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:29d919095f0ff19e2ca4cb90d8099592fe32c98b1b6ba19a14bbeb584049d87f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:ae1f50d9b0f5060bc6d2596a08c488776f6b79e54b46e1ac341571878bec0416
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:8950a2b0bb20fe19eaa204b5855b3bbe14ba92362d20955ef859ee3c36c94edf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:50dbfd305c1d7d7510fc5c11fdc088df99aced0b9a3d0d05c11dcb2c1b003e41
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:f3d4ac44c0cb4fe9b3a01b372200fb9903dad4b40748c6792a10f1d74871bd5b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:ee7e6c03ef3d5b90502966a32f1e93b813e23212b7e08765874a67f89992c0cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:e8fbad3a5a082b40d111a4e2fa6d53685ee49edaa89e1bf420877b288ca92912
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:dca71f15141457e3c157ded957f2169ddf69595467c68ee144c4884af748ce77
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:71db6eaa099ff0c9a23900609cb96d48397f50e8ff769d6ade98ce1b2eb88d45
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:7ec6ead3d3584f4307a150e6c6ca950f1fdbde2aa1799e895c23b3881ccee349
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:a858eb71a49e72c1cc439c75b870e8b1e6aea6f901b80495850f12f18cf518c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:c5afef8ee197cdb6eb966f1d1e0936827eb72955fd45be703f0e306b74223969