Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.4-debian-dev, 2.4-debian13-dev, 2.4-dev, 2.4.2-debian-dev, 2.4.2-debian13-dev, 2.4.2-dev

Index digest:

sha256:deb02dca1abc39efedacf87cf0b8e13af824bed923a6c4d62d1411dd81c0e20b

Manifest digest:

sha256:dc8ce0a8f780057dfd0fa4dcc706a99c4deec138d469d0e4fe4a2052cfc5c9c7

Size

59.63 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
14

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:7acddde92c9e6dfb0b4de5e35cca8af1191abd0613ba838f88aa692cb6e490bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:7880a3a67ce901adcf518d2f15528a833609303ba8edd41134a7454c4a8f6c37
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:f73f9d99e0375e78c0d41fe6641b92e3b3c67886ec2bd62c5b035c0ddbccd258
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:8cd5e353accc7a14728c2e6f2744eca600450d98035bcc427ff7219b6a9796ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:bc4f9badb3839127a97348373bbf9fc779612fd2a8d5b6dc065f87d0c79f3477
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:966836d74abb65bcd04789b6523b0ced51eec561933f49ac04d3d77bce80a115
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:176e61b481bb24e1cc0e53a01f3dbaa5b4ffa5ddda79113394de9111ad692fcf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:8c95a620245d5c3d9ca7ea5df5933341ab9ceba55fd27b5995e3957ab26a83b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:86f0fc26b1518c8b2648576fcb2c7a65ca6d194b11290dbc78a48079e7cea5cc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:5ea828cdab5976a23f26938ab123805a0f2a198a38aa227bb15046a9689cea4e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:b24fe6da8d6e0b22da55f47ecdcc8a54a1a061b2beddb91f76aa3b13c84d44f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:0748f5c2b14aef70b9ed0c5c175a39c0250e48f4e58e6557e5e3c7206b3cc98e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:5cb4225147d8d6286cf1d3cf9c87ff2774111e152f96f20a7a777c220dbd235b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:20e2d2a63e14a1abf5b4cd00f92ae3e412b74dd47efe803c3c2331a47a01c48a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:a4f2b29327ad5cd3d2bac762060c9d872828bf8175a376823c29cda6368e77da