dhi.io/crossplane
2-debian-dev, 2-debian13-dev, 2-dev, 2.4-debian-dev, 2.4-debian13-dev, 2.4-dev, 2.4.2-debian-dev, 2.4.2-debian13-dev, 2.4.2-dev
sha256:5b0a35c3bab086b42cbb941acd787b85f012e0ccb10f06f915d67e52496a869c
Manifest digest:sha256:fa4c65e9cb0692c21ed07fa8efb3417e908ab2d4082f02716297d5a9775b3ade
Size
59.62 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crossplane:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crossplane:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crossplane@sha256:4906f2385159ac32ad08cef16b94c01dfad9ac682cfce171d02aeb98651c4248 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crossplane@sha256:0ce47528a18b2b65407a3a7bf437ba11fa1e2ecaa70e47acc1cfed7cd46fa432 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crossplane@sha256:ab7672cc74b311807b7284fc760a0c828d50dd6fe5dc48651b699267a78ec446 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crossplane@sha256:292d75bc543c90560d845dcef4569ab3d5dcdad00955d3c9b786c336ab592899 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crossplane@sha256:878bf5c065bbeb4bf0ebaa54bb90b4405922a94104bb0990664d5f31fee63366 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crossplane@sha256:df7ba1b250dc81112d3be2e5d0254906dbfb95b04289f126d2f87b46dc012f62 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crossplane@sha256:1f9007efeec8bf77abeb203506417f041f9ebc7e29a1b548a1dd24129dbaed24 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crossplane@sha256:8fa5dbdb60b04376dc31217da8c61dd6cdfb28571e37cdaead5201248c2e168d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crossplane@sha256:f90494bc3b5106fbf6d2d50b15b8cd5fc975588f5d3b6ced541b83035a951ad1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crossplane@sha256:e100f789417df0f9326eaa197fa8d5c394a125fdbe4b7a23f3ec58e64573e666 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crossplane@sha256:60fbb21aaf814b3a152b5372aa6aedc277ffb03ca4f176d4e7b2496c13056ba6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crossplane@sha256:8b1ff6abba908665078a1f249b60d59908cc234cbc8a75c3923ac303f2c11e99 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crossplane@sha256:3507d1117b18520ef195bb35f918df2345afb700403978f114ebd854b5f9c0fa |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crossplane@sha256:0448e833301b5f1bdb4eee72c52237ded4461ec277a740d4ab55df11febb72d1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crossplane@sha256:45ab8f20d084541c1c5d0f677fc3b5aa391fd37dfa216feee5e5e28b7d84b26f |