Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.8-debian-fips-dev, 2.1.8-debian13-fips-dev, 2.1.8-fips-dev

Index digest:

sha256:6328a622dc6996a242e7238bb46b1d2057378ccff89743b4ef784dc7be6f06d1

Manifest digest:

sha256:da4c341a09e30fa27f459aa3de48e89aa264eed2de4cad936475947ada2ea2bc

Size

61.03 MB

Last pushed

11 hours ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:5fc691654bc9bde967f0d1fc8b2df97ebb03bf7fe310c2298b015583f2e4a4f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:772f7c12abd16309ffc5109340cccc7f7873ef7e92807d9e189d3c9c87334d69
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:aff860542e681d683ab8cc1014cefb9bd9f13a8a2d17f425f28843d0cc19b79b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:5196517c405b2516ac81fefc378917f91dd706130ece607dfc2dc8729e387387
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:c358d92f1da82e5a98dfd2683f449b79eb35b0297d5ccfcc03c7b29a63592cf9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:16affab2d94dbe3cf97c0d615cfbd78db620d547f0dc5d02774fd830cbea54d2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:008f779b831c1b6eb9a5e2fa6a2e54ee4f359023f575c6f12454cc1c46a3dd66
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:73fa3588189e678a150706003c83483886a0c74ac18f759728a0787a7ea323a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:7c96779fa291a76112295deb3087e2603d862795817d750a1fe623280f6e0597
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:273cca104c45aa8432ec4a2a5c5c4b5f17cf8d2ae617bb5506019741ffe7df4e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:89ae1da2bfe8176824dd05f57ed6e121f546b8179ef2eb96fce40810a01ffee1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:25b0b28f80802e61cec189bc52da1f58e5c2778c55f4c2214cc5792ec6d9c300
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:dcac18d1e223c10ef19a1b18047b4c3efe33477dfbb8b77286ac20b75b186df3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:eea081bd94b16fca2f7a6612c1b34e6e125af17d7f399edbdde77f20ec552dcb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:5090c09bb9011baa2855e0ff1ba99bdc41ace7583f58c517225bb82b290f9d30
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:c66e88b290daf3f9f43c917def471101bb9269a3de8503d350d8a28c910502f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:d9dfac5d9ae8ebc4041b8343bd8b1dbd1c2c433b194bbc793b660fc237cc1853