Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x

CIS
linux/amd64
debian 13
Tags:

2.2, 2.2-debian, 2.2-debian13, 2.2.6, 2.2.6-debian, 2.2.6-debian13

Index digest:

sha256:f52d9ea40af881adaedb9d0dc3e27c70eaef0be77037c05bed48aea558fb0a2d

Manifest digest:

sha256:7661fd2916604bfd8b0e21ac7c8c980c4fc59408a1edbf84911944f2eb3cf487

Size

26.24 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:1f4f7a02000a143047c3420c2dc8e9856b8ca02a0d5e9a1e23643a9304c80ab0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:6a85d7c513a1edd983481ac8cc24fa0bf71da36016996bd07ddaf04cc55aedfe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:3b96ebf7038bbf4415bdc5d072169c074e75db3d6583696f1c862cf4f3fb32b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:e0397787d8c9d49f109d713da916e6daa30c69d39707ae5fbaee30d318ae4f59
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:0c1e8bffb9af28e4aed36fe898fcba3fad9df93ec22b75ed8a0d871b54c2293b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:750077144157880fcb02251bd38c6f9d839f868039436114a0565bb00343f1e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:f9d8811ebda708f6cf1fb878c822971bf56fd94f261069a644b8907f63cdb62a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:fa69a00bb3a3f12e01d22c4db0f6546c913d18c27947bce1523d160417f8cfbe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:42dc923492fef44d59a3842222e024065bdf69f2e73a6b202645e6bce4ba4500
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:eafc2105dca1eafc8adc4b86761eb8ace11022dbfb09bc7706bc93d63f0205ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:d6a9bd2618ca699114c3ca8726dc52d626a439448101e3a55cc0f256567ae065
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:bfce0b10dc8dc6163fde7a453bce7993312846373d774ab98dab450f63d1c789
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:ad86a97db6254a8022dcff950c9c627b2d3a178f53ad6e19ced9250c1e441446
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:0b15855bdff1a284fb6b82e73b8cba5a3412b685d734d2061b79dab62f3a95fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:d22f02a42f7b00701752d8eef6b01f038f8fd19733173e6b05ad1115000aa935