dhi.io/crossplane
2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.6-debian-dev, 2.2.6-debian13-dev, 2.2.6-dev
sha256:1b54a5f9cee7027cc8d7c9193d30fad629ede6d58e90c6561783ce3938849b54
Manifest digest:sha256:90a9bbb41b491be93b20984d4d994c21f2a81b6bb0e61768ae381eff13c70684
Size
59.36 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crossplane:2.2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crossplane:2.2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crossplane@sha256:ba1aa59f26c7d69d9d2bcf0a614bf383e05888606df7313e5ba5b2bcdabe0730 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crossplane@sha256:6877c9c4ab827b4f43de02fc0a9b01a9085767805b020530235b73f44e3b93d5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crossplane@sha256:26e9840ffc3a23c2aaf8a37e488f4a194f701bded7ba00785c5b515b090636ef |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crossplane@sha256:a6e5566b48dc78a0443cf0089ea5d833a89dcd202adadeb86aed9e0ffa98a512 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crossplane@sha256:f7a400aeae8914c5f1e14b2e4e8d18855b448aaa75f97cc555b8337064377a64 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crossplane@sha256:2072b801e00f325803d9fb3713f5efbee42f4d05a8f7732968f28293f7789bcd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crossplane@sha256:2f42a8e14889504817a2bb020ed0c6b0f09fe5693c7614ab5fa4cdee563538e0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crossplane@sha256:ef087c0aeadcae8a50727bdc81a9c1a61437c89a5f7c7ce0b07a47b1087e86c4 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crossplane@sha256:ff431163547048fec50977b075379f9084ceb035aa87b6be609664978874b8f7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crossplane@sha256:1e69972d26197145c0fe8506025b6952a82cb5704669aa9388264cdf4c0cb689 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crossplane@sha256:2c4bed4ddb9dc15139146bd03f55d274a4b9c1169f350c87e348d2194ddaca5d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crossplane@sha256:d764458d2be23ca483130f7fba52b73dba6b689e42154ff76786914db7ac5fc9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crossplane@sha256:7747822f57d82cc3a41e4edf51e61305f4fb2a88856d7685c15acb30f3ce8d5e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crossplane@sha256:c4bc291950bd775589ce920ec059e7c5fc457956b8a22a0d1a2bae00a7e7abde |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crossplane@sha256:2f9c145ad5fb751f265925655cd39e0c016f514a43d61ba3b84a554ec0f63f85 |