dhi.io/crane
0-alpine3.23-fips, 0.22-alpine3.23-fips, 0.22.1-alpine3.23-fips
sha256:7e64bc57fdacdfb1137f9c0352747e928967a80820e2ce3044829054be222a96
Manifest digest:sha256:5e9cc10433ef255b5f61c175d926177ad2c6a4e000211d9ad3bb26da84f1f862
Size
7.87 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crane:0-alpine3.23-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crane:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crane@sha256:6764f418dc960e2f2104148b92093b8a9c268d3e85f8e8f975772cf21255f4f4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crane@sha256:b039fce82a2358586513a7fc553d886eecd64345d7722d27e760112b9637aa29 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/crane@sha256:fdd455ac5af3044b7fa64153b99ba40b4f6c106f9c46bc14bfbd21f11d6c41c4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crane@sha256:f2644270f9239c519f9464bf01088b7fb922170ed9211f9196e8a411b94a3ff8 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/crane@sha256:fa88326c5c944afc04a8def0f86a1264b01c23a4d147f6f0c00ba81e096110b6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crane@sha256:1b4d6f1ebf354298120d958cd916d31d0f5a8a24323d1abbe056b17eb78c30a7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crane@sha256:228587410330bb011e54634ab8a063183734abaf4289d240f6d9c977b356a3dd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crane@sha256:c18ec9c75bca5af4fa7f55fe3e66c5cafb70ed48eabcfba19211384ff9d9ff90 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crane@sha256:ffeb0201b5273753b1ca3ee697501b95fea27fd1090cc944b02bdb8d0ffd4c37 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crane@sha256:465c547dac0cd016cb25a662604b604cc0ff5123c3569bc2880c599ff7f4152c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crane@sha256:709c93e385023c5615dd52f5554248cf805bbd02cfaa8b37cb512237db3c2592 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crane@sha256:6533c4aa7c9176b2eff1009c6b273d1aa6a89a6b96f02272025b55fcb919cb25 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crane@sha256:eac8811ba67c70c34d3c55ad1ea53c23441ae6e535aa9c6d5111d36cee8d30c1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crane@sha256:c788fbcafcf7311f1dbd6499a74731cd0be1bc63f019378c431da5786c60876a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crane@sha256:5d5afb06922ed652cf5737840dacbe1b1e1e2bda34fe163e6945a3f2fb3865ca |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crane@sha256:f11b0b9f0fe1074836308d631f377b193191c242c0211d825b7ec1569470817b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crane@sha256:a1aa36439bd5e693bea639f3061589b1a37317da7a07f1f4da4c918353e756cc |