dhi.io/crane
0-alpine3.23-fips-dev, 0.22-alpine3.23-fips-dev, 0.22.1-alpine3.23-fips-dev
sha256:deac5ad48c92df9e8d6a0ab7e6c8da35ea678428344487622c86981bc701d9e5
Manifest digest:sha256:8945c6a06fa07682b71c14f0fbf2105da465341b2be7aa0945f14a3401f78264
Size
8.71 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crane:0-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crane:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crane@sha256:4ab48c2183619d848c62d57064d7bad5084e4442afe986221062d08641fc6648 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crane@sha256:1b83166b81f5ad680326e5042e9d1a11dd9b7afa4be6d3c2f5f361848d91a149 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/crane@sha256:0fb303c13af3979aeef6cfc113d53998a80b2335462220fac354c51354bef3d1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crane@sha256:891b75a045587a786c614c0143b1648d04418192e8c47c8834555370bb254beb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/crane@sha256:5a8235faea181a096741b7c72b7df2e355affb603e5140b4220f1dde74e4ae92 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crane@sha256:89482f7761af05f02f913858b3e1ee9ae9a7850de90f09e296ad7b1b26136e06 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crane@sha256:f7bdbd819c676d0dd1478ea01a4476ba4fa073174f047ec589ee0b4c49bf041d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crane@sha256:9f6142297c8721978d38297912fbc9c9d3e52c3a6bcc01f2afb1a328a2b1e112 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crane@sha256:9c5b32487385626bce19c850ed9287833a1576d24d79487eb9b0b41359f32dc7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crane@sha256:75115c77b777c3565005030e87b93d476ed09c81c8d218cefa7aa0eab1b858ef |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crane@sha256:c2a6644811c06774f6e6320af4082947dd79e5d4e052eafc45bf8254a7702483 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crane@sha256:90daebd234db978bbbb1672fe73115c5a5460b933932c02d6c64c3a8d0f3201c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crane@sha256:65bb30f62ef0f5d397eaa0c21e9d893791ec4bb85e68c5c17010923d2642e6d2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crane@sha256:08d7c3b446f1665d06fef0a1c0fa16f040575a448c2e913b57f8fedbcc775c7c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crane@sha256:f8a48dfe3ca398886ca62bb2c4e074ab5cb45efc24038c356a1db39ca6bc3e94 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crane@sha256:21a9304c56fd678397f801ec4afc886d3bf93d27ac65ce9d47ba4482f0901977 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crane@sha256:7a4fafbba2fa82d523f315ca2500b06a78cbb2e27dbd4e705f455078e8226d6f |