dhi.io/crane
0-alpine3.23-dev, 0.22-alpine3.23-dev, 0.22.1-alpine3.23-dev
sha256:30a3403d9c0a15a37dc544d5a1a390f014e0e77e0b970e968f362fa665fbba2c
Manifest digest:sha256:9c0f5b0dc1647a90b2875e203572117d044f824b318b7e06ddcdf5f4eb6297ba
Size
7.85 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crane:0-alpine3.23-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crane:0-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crane@sha256:979036988012af1a639baccd36d10b1a2417c6a962a18b4fa775d61d0a2aa5bd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crane@sha256:2ba9c19f575edf520f2cb7707ee0986979346427746cf9cd23fc5efc22e24e31 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crane@sha256:ad73cf85ae125e284137bc674cddcd111e3e800c85a05e6b153fb10f5df6ae85 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crane@sha256:e266dcd986227643342aa416538b6fb6eaa21f67de2a52aef997ad158e801a2c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crane@sha256:fb657bf8cb6c4fd0b1800c3f653e842a006ce9bd916789e89f5a6e5eab755530 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crane@sha256:78fb819b83bf4b79647c65a02a12218a2d1893ea630532f2c1509b0a0e1fd23e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crane@sha256:908e15333a06577a59ca7b08558bd570af333a0b606f8892c4d013df2be819a0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crane@sha256:04a3358f26605327eb61e5c31064bd0abce3489c50913d6e1a362021994e612f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crane@sha256:5e8f2ed1c59318dbe7113696ec418e1b4f5529ff1c6aa0de67bd6a735991ab44 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crane@sha256:9efadcbe2859fbc48cb0ddef2bcca994b7ced118379d9427184336a95473673c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crane@sha256:bc7d211c7b095821521cfa5c06e5ef72cb81de2980ba24e1fc9fbb3d4c9e1709 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crane@sha256:02343fd1cc115aefec1077d16953db06af50db281fb438b18516ed514c5d4bba |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crane@sha256:1d68f5114c49cfa7e7607a338d1c4e97583efb27b93f4bc03ff80d9f3e8afdd8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crane@sha256:20af82777297ab191c812ea5832d65df804c2ca79ecb22b42753009e262fa4c9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crane@sha256:b8910344709b99e99af74731ea0be3183afbab1618dea537ed84beeeb5c4724c |