Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.8-debian-fips-dev, 2.1.8-debian13-fips-dev, 2.1.8-fips-dev

Index digest:

sha256:103263729d7612ad79135c8b14b515a9444811756116a1cc9f516e436e30a9b0

Manifest digest:

sha256:e365b58559c738a6ac53efe86324889b4cc04ebe5a96683af4f5e355712fd7a9

Size

61.00 MB

Last pushed

3 days ago

Vulnerabilities

1
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:d873eec60107e5647bb3c1db947ed68b7938d0eb9bbbb05fb633e62fbdea2b75
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:8a88c3f98258c8f441df3c09d5323296229c090f09629bf6adb7f1379ff89725
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:8658a54dabaeb1c7b40686dbe5ee00d2099938c059923660c3f88ca4e0212f3f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:1b490af6cece015b7866baf4c1d4ebf2364e6309a170478aa095ccdce83b3084
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:06d302e6d4c13eb6a303b2e6bac859e739448a4b4dd49fcb359b7165c19d9eb1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:f3f08f20816bf5b70c5b66ee2b9878395d14da01516fd6b9e1167afb96cdd137
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:9aea1471e4dced0c045f326411da304e97268853a71dd25d6509ba7212868bf8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:8e48faf4c88a6b9ab33aefcb497c2ece35c3a69ab394f1776668713a2250a834
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:30b41ef13e1b1e78e206a681e7586b2b26c4e5b14bd1769923e161a311522a5f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:68a6ff8d4eec17acb7e677ed8e02fedec2ea165de63d2f02ecd06a7291caa8b6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:00eae8fae37e58001b3c1e261cbf712814d1d8483387300eef95bb01a83224a4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:17bac8a519bfd489065cda8fd9d86357beb9f2df87fa9f4477267710de460905
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:24ffc1326fd90265ed8d62596d3ac272307be389e759aae26c086791800188bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:74f04e4d74c5054cbc545ceba777784b99ab0dc04896afa96d5e94ce77f6e8d2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:37d0db18254061159bb0d7fbb4955d1fe887c443c0f3d1365f856a533bd17142
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:bbe01667063bb3a7a6102b05f66b0ccdd91e9edfdb482812bc0c8049bf44f6fe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:aeb3aca8427a9374069be020ceb4469f53239577a1a020bc79b76fd00ca58c91