Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.6-debian-dev, 2.2.6-debian13-dev, 2.2.6-dev

Index digest:

sha256:b8d7b6651f7682f8d8a5fc657f906c5f7d9fcebad8ad8153986c3d19173bf8d6

Manifest digest:

sha256:bb6eaeacb446cb3df26e14b613fb5afe452bd53dc52619d2c3eec05589581ddd

Size

59.37 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:8438b2e1b7479c6ff23bc566945231b6ff6c57216d3b43a419c62d0951b3562f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:9946a62aaf4b178eea4979d02b5b754bbe038a7b65f691f1c0507dbb0d0ab69b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:40e00a82a201880862f907a658de0c66c14e4f4eee893b37d4ffb0c3820df3e8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:1cd9753ab022fff4fe67ef3069f09e636816c0d3989afd10733d584fdfd3fba1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:a084cd1f03fead2e74b669c3f397d754ca876b62a1ea3f32ea61b19a8644c552
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:502a88a282e119743823f0d9e382b87234032f4076041af3b14b3589b6ca996b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:fa23bcbd5cf56c994d0b615f4c55b17feb8e80cf6d2e3ecd91f5eebf288dc918
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:cf45aa3d79b12ea0c4ed7550c0f046ed6cd8d078293449ebe933d036843d9746
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:e595190fa76ad67764d813ba7148de7b034578619486015e9b6b4ccdec3fac25
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:860c07079cd52f9b2147c590d2e387c1325fe6bbaac936d1ad3e080242ff4adb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:5257531fb1c365c4107ce104e3d3305cc41593d1d2a6bd333030cbff2bf69310
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:7baefdfd23dabd56e55f25a9ec85b12c276108d421337403c6eb85afec48ffd1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:0178370dad45b7f049449a0bbd0d854245107889c366ba9cc2957a4d4a48a39f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:abdae7530f3ea5050c2ff3cf93ac59ab6f5e35831c2d4fe732606824d58c75bc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:2769aac2b1bfeaf750b7511e04c8e047fc78100ba7771d549c921bd7093bc66f