Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.2-debian-fips-dev, 2.4.2-debian13-fips-dev, 2.4.2-fips-dev

Index digest:

sha256:f20badaee8f91c1a76ede371501781feacb6dcabcb76c8fbef851f6900f17063

Manifest digest:

sha256:e72c25552cf9f622fc528029208a752c794e3da5b0f1cf6a1508b3aa9d777481

Size

60.45 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:c16a70371cdf8bca83320375a2aa12a09e667fccaf278588589c3c86852789db
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:f778dee69842f2a46c6736560559315169610665c1a549342094334c8858c48f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:5ffcbc6840ad63abd7f8abc2520f449bba8c66772a3461dc48f6223b04bbd657
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:dcf00df662317ca4ad5a403d9a67273d4486029c6bf7e0eb9f82daa8e500ed63
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:861ca3537640ac28bda6b4449b0b1382d2d0eee7d87ad3a8e0a4fda7d02460ea
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:e0d38d47996a74f58f7fe8b7886ae064bfb8b83543f9f2c788769107eed103fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:9ab74d5ac565c0e75d25d0dacebceaf6af50612998055700dbe9bcfd316e6bbd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:4e5a1658f0adf75d1c630911ff13281d074032a0ab97d323621f2bc14c89cb1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:4a85554d033a6ed9e6f5f2ac1a807ad745f5e3d26d6e1021948dd5ca9daa26b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:0cd5fed71f0e0bec01713f680f57f4f9b4e0bef3dc7e45ec0bbb3c8b17b10a02
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:8d198eb5d3fb2238b59f89f4096cd5cb368d4263f4b593cb6c7d31a61004228e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:50513578ef338df0c440c8e86796cccbceccf3983268df0dd7621991ce46e3e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:3ae94174e515aba5e773025234a8ae2ca493a1f79eae1c6689d599c9babbbd0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:7ea4aa4908cb2829d4db6e6014acfc3e40d808eff3e5ad51036e5ca6ca3d26c1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:628576d14abd3ea170341ce8d4d818e9f0483281ee65f744e8cd46343aecca5a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:eb376e0647e321e04b40a939710e57cf82b4f2f34b1086cdb354addb57ab1f28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:287a7ca95c8811597fe129450f51616b34db726e13c3ee26d4914c31e08bc1f3