Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x

CIS
linux/amd64
debian 13
Tags:

2.3, 2.3-debian, 2.3-debian13, 2.3.6, 2.3.6-debian, 2.3.6-debian13

Index digest:

sha256:22c3aa4b7f716aa1a3bbda3d347c2950e2c590e58712c2f14f97b4062f7b6fa5

Manifest digest:

sha256:4cb0be402697a022da6a95cafbc1ccbcb0a6bc9411ac3892679f6754960670b1

Size

26.32 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:8cad58c9d367ad89c99d2be117cdb49c7c9fa21e87ea727d50e088a83628ba19
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:475aa8d26162732c2eee8ffca4c1c7dc17d379300413a535a408dcf63616e498
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:747516c948a7df5cafa1ba4aed43dcd0e96a67fe7aadf446daf27a39676a1410
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:8c3a1ff2f036100d963ded665ab2025c673a99782c11216af93bc227170fe08d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:f6f9341733f2c64435d2acc0834835541f8d4f259f8bae913f5b5af330e529d2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:6db6f30e9b4be3e37e33cbbe1c01fb61c385fdd52952de559868ae14329119e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:9f7b345786aa923ebe03714d11d62ebd0b103361b0353c17c74a86248a24d9e7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:1b76fc0894b750360546e8e1a285b7c5f6518ab87e77a8cc7b3d2b94b1a21685
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:4399c3c8ff92b19aa7e70d5cac2a1119881e12f16045e53d450b90b19beebe2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:2c979e62ae5d849ffb922b5e477afd6483f30c62957f94210c9488cd87ead678
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:f670f7df584f8700d58239e7d03c7be9df46396a4902294213b680d849aa8b12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:95b47fe3fa67ad32fdbe0c25bb0b1fd1d880094cfe48238f8de1d4e1036677e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:87b0819801be365fb4f1cf82fe9afd654abc411718effeeea64d55cd95c288ba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:b87fb8623ac9cd0e6bbd84bee6b396606315fcaf46d7992a2321bb8439c22138
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:a053cad5fe942a04005dafc81e4ef3ed590e84cddf4fce3ccf859c82c6ea0792