Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.3-debian-fips, 2.3-debian13-fips, 2.3-fips, 2.3.5-debian-fips, 2.3.5-debian13-fips, 2.3.5-fips

Index digest:

sha256:92775aeb556150b05f12c49b92ce2839e2af70b7aec2b6059486137b224066e8

Manifest digest:

sha256:c961f602f2830f5305a6c7028cc9c1231d0c4e50d873cfb560b7c4d3ed349d3b

Size

26.86 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:6fc47630be43720e16846af9a49b151ce172a6b11594eb4acbd975b4125fb738
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:f7f585d1e72296532f9b90faf399d70907212bb9e3d6a4f3b49cc4e03394a623
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:7c6493542ea098cfc843152410901dab47f505402c7dd8858426cdb2ffc5a966
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:83c7a042bb94db425013f0e1087f8cab7971090eb34295c8d9b9c6082459ce92
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:6f47a368efde751a556b13649ebfec1c031c4a952c93f4d2e181333952da24d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:aa83d59f31394df779003500c0b6ee46f723c387dea748cb33f3fd53f503a608
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:77fc76de2877e622e99203992ad9936214ea391b260c19c1aeec626d0d010ed0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:2574f418ad4aaba8d47debf52b171a4dde07ddf2805c8cb51ab55e2ee1e40346
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:64369b34122d30e2b4299506a3b72dfb95264698f2dbbb9624876fb98989c3b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:8273077513fe8e0d3a8ecbc430a99ca1b71f193045890235d23e03e3750b974b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:54b4588924822299cab18c21496a78f3b8c76d450a46f219cd26a0843792d963
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:c7869522a5074c7db22bc3093cc56b1a5c798e7b27ab9491d2c473d2a3961a07
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:df729a8ded1ada57eb06895878563b46159283108d91ef2fa8cee2b5d4dd865b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:a0239294613d1ded46abd57651c46dc0c3a0ea9a71deb52ace03266a954fa5a9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:890f707ac4249b9999664fd6e8f7547d9ee02fa30370bc2d4fe492a4d8e5afcc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:4591d4f814943dc2cb8d062a1e9841a451405652ab42ab924fe411d102badf30
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:eaf0a68ff8b75344dced1fcfdb0b147011263bbd968e7611b955c7ac1853affa