Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

2.3-debian-dev, 2.3-debian13-dev, 2.3-dev, 2.3.6-debian-dev, 2.3.6-debian13-dev, 2.3.6-dev

Index digest:

sha256:957795d94a8b05ab82749ec15f01a7edddf72c012f7938a1b403080ad511c8d1

Manifest digest:

sha256:bebe85e75ffdc4463f43e473f699bf1b80a38f5367f5ec5a7eed5c8526078b95

Size

59.54 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:3653e42b65a87ba6694535574a4618a7c1c1931f2150eb2074413ccacf12866b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:3e3dd3c297c84b5279bf4683fa1ceeb167ad348214d66c0ba8304bcd6e6aaee7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:dc6934002dcb1b9a58b93f3ef781bb87dcc9960b6dfe71a1c6ae439dd2ad2402
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:3874d90ea7e4db182f76a923e21a5297dd377c1aad837e9e968810c8c1e16f5f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:18889849c638faf1465bfb14878710e296150e0d4ceb4ae1bd03b6dd897af860
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:2beeb98006c8ceecfb786f3c81d427d6b356cb2da7ac5af20490bf6020cb428c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:25406a4914fc98b74e2c70790696d63d4f626484f231e9b1976b2869451a7a18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:c18efab0601805df85a8a276c09d18b55de3f124604d3b60587153cba7c8c2fa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:8704eafa403e61d7ae4ee27164fbbb2ed2d59d3b9fa06483614fa24d619b3235
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:0aa9d8b23b10624a7fa3d5eed0e49f9652a164d139b9d5a6724a52a44e03af5a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:f38e542c99eeee7423b937fc7bda26272a7e8854ad3249916062531901c8fb6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:8010beb6495ecb33c9b04bf357321277484c617982011717aa2ee07ef413dd86
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:17c032411895bda8c36d1f0d09f2ac2b8fbb9728fed34ae123bdcbd97d6b95ed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:a7e1f04319314dd1451abdd7e59ed64e22092fe5954dbd384d31b37e346fca63
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:691b8eda118e5a227329b0624b2aa902844b0f58c36bbd26ed842869d0a19b42