Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.2-debian-fips-dev, 2.4.2-debian13-fips-dev, 2.4.2-fips-dev

Index digest:

sha256:d8a5bdd81303700254f1de0e3a9c5a963c4ad2842a64e53f13d2cff0bbe2cd8b

Manifest digest:

sha256:1ea1653cc0ae68b04cfd583e6b5a7c222e15e3dbe86dbba9dc4424fb402b02e0

Size

60.40 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
14

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:8c7d5b7677c3d7f2ad4f9b6eeff7daea54592577cffd00e91b4c44db48060ebe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:c8171b6fb6b09849fae59ce76913b08cff7a11ad23999a10aad808882a95785c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:92a76fae48d6bc1c8e1ac02f69d744ebb6f3f149d7da7e76a80c2777a5dc61d0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:46f655662ff2b36fb1c20e38385573159d8131f93c1b043339b7dbf4c1b6adeb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:ec016e941d19d9ba4be814e7e44aca0942cf07f38235404d1c3558fe6b75c2fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:24bc41087ff5cd2bc8c4c05723068e394df49f3eb7508a82afe16af0b589a2ed
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:f283d6761482cdedec24b22f38b991ea8b46cb7858aefdfd94c4fd05f5f7c2a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:5bfcd11550bf0d0d4fd65fc36f838c5b2ac5cc51faabbfa7ea9b2eb5efefdb6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:2a58b84108924e4f1849afa20dafd77f0a32adce830287829b275ab5539d4020
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:bab36ec1d888a9e9b389788ea106ad3043d7512f799494b3f77009b514b8a095
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:d0e75f30030ecea204a544aec2027f2519912279d96d3037829070be9734fb53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:19848b227827b55a19015902fe4a8f9ac55e882cc21e801c7b71ff38db6138eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:b670bce1a54877592930a48ece6659cbd88d37d5c66019718e4365b37e186a92
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:b9dcccac28e712f54b12541126e3c2e47ff9360ca193c75d7e9ec380bbd5574d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:714dd4ceffba7b61a611a71f7e631f33837a2eac3736660ca32dfabb5d0da95a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:cd0533a02c205495891764310d476c8bddba6b510a8f9c0c8dd9651397beffe2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:6bbdd0f192966a99e0bac86c4e0aea16883be121b2f5cd647224080f21e96954