Sign inSign up
Crane

dhi.io/crane

Crane 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.22-alpine-fips-dev, 0.22-alpine3.24-fips-dev, 0.22.1-alpine-fips-dev, 0.22.1-alpine3.24-fips-dev

Index digest:

sha256:710ec82fb2899aa54d0a5b50cd3da59b81833079d183f59f849880386292d1f4

Manifest digest:

sha256:0082ef2e5e4bdec9a04658b69a908b578dc096437039b55f2d6cba43443725e8

Size

8.71 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:b2adebdde3dd7a03faad3bb864ec640af830dd1930f153a0b90c2590adf506d4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:db3018a497afb46840a4694af6b19dd730700b0463d83136fda1f710d56db1df
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crane@sha256:926778c6a62b9cb16b54a1cec8d6910d8812340a1f2ae93b13f65150e327c46a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:b4c137c190fade2749c34cc4b2dae65a48c9bc98498029e156ed9ce0c184bd9c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crane@sha256:97576336bd91032b2ce5ad55c5d307bf890665200af6c701f844db42e3a6eda3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:aca2fe55e1ddad04d9b83c9c7dc5be64bbdd72bfaa17d12ebe7f39889dce7707
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:c96cd373eb8d19cad5bb7783f4c2c41a6d372ac488f99e662be8388f249998ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:9c55c504565738ba1e367ecd268b43ae5d0da6f7c2059202ad0725fbf2285076
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:98c551050480c7cd63629ecf3cbdbd7c05267290ed58030b30409b554095cca5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:c570318770fa42f0f5719c18ac43d4386cb1ce574152d4bc47e276ca13e10ac0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:4ca126ada20eab92390449aecbb3571c6e3de31b781bffbf43cdcf312841c227
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:b0d571851256143fb3598f2991318cbdbd15460e1e710f9e1d2cb7e1dc7de021
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:e6dbc1926d6d482848c9b43fd28cefe6389dd0d727d65c377558a05013253a96
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:6ff5578ea1aeff86c7401b0c3854c2d01fdd986ae46e6331c6eb6e1163605a5c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:cc274ae52771d6e4019d41c2bd1a6692402a3c1da36292c1a71463d2aa6b17b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:bafc0e9f0c50914586762bc765c66466d7209a4517a88a9ed5495feb34b01fdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:2a8a192f8f8fcee81e8c5ae5ec62e8fef3120e7ad4359a19fae1e827a0670971