Sign inSign up
Crane

dhi.io/crane

Crane 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.22-alpine3.23-fips-dev, 0.22.1-alpine3.23-fips-dev

Index digest:

sha256:deac5ad48c92df9e8d6a0ab7e6c8da35ea678428344487622c86981bc701d9e5

Manifest digest:

sha256:8945c6a06fa07682b71c14f0fbf2105da465341b2be7aa0945f14a3401f78264

Size

8.71 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:4ab48c2183619d848c62d57064d7bad5084e4442afe986221062d08641fc6648
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:1b83166b81f5ad680326e5042e9d1a11dd9b7afa4be6d3c2f5f361848d91a149
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crane@sha256:0fb303c13af3979aeef6cfc113d53998a80b2335462220fac354c51354bef3d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:891b75a045587a786c614c0143b1648d04418192e8c47c8834555370bb254beb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crane@sha256:5a8235faea181a096741b7c72b7df2e355affb603e5140b4220f1dde74e4ae92
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:89482f7761af05f02f913858b3e1ee9ae9a7850de90f09e296ad7b1b26136e06
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:f7bdbd819c676d0dd1478ea01a4476ba4fa073174f047ec589ee0b4c49bf041d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:9f6142297c8721978d38297912fbc9c9d3e52c3a6bcc01f2afb1a328a2b1e112
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:9c5b32487385626bce19c850ed9287833a1576d24d79487eb9b0b41359f32dc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:75115c77b777c3565005030e87b93d476ed09c81c8d218cefa7aa0eab1b858ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:c2a6644811c06774f6e6320af4082947dd79e5d4e052eafc45bf8254a7702483
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:90daebd234db978bbbb1672fe73115c5a5460b933932c02d6c64c3a8d0f3201c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:65bb30f62ef0f5d397eaa0c21e9d893791ec4bb85e68c5c17010923d2642e6d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:08d7c3b446f1665d06fef0a1c0fa16f040575a448c2e913b57f8fedbcc775c7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:f8a48dfe3ca398886ca62bb2c4e074ab5cb45efc24038c356a1db39ca6bc3e94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:21a9304c56fd678397f801ec4afc886d3bf93d27ac65ce9d47ba4482f0901977
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:7a4fafbba2fa82d523f315ca2500b06a78cbb2e27dbd4e705f455078e8226d6f