Sign inSign up
Crane

dhi.io/crane

Crane 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.22-alpine, 0.22-alpine3.24, 0.22.1-alpine, 0.22.1-alpine3.24

Index digest:

sha256:c9f8d17da00e046c1150072bc79170729ac8839ef6c1678a1f89777ca61ded24

Manifest digest:

sha256:b0df74dddc92e58cd9ce4302427896451d2730b66e3e5375ae34c1cda3f571e9

Size

4.48 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crane:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crane:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crane@sha256:e3da13c3b069f848e0964f5a234c27e5706b36cdcc36c3f5185ee72af2216206
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crane@sha256:dc729ab4e66bc2916a8d43962a6452d527f507375e6dfa3b24b24db3ebf9f92c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crane@sha256:0efedf31975048030d1bdca3e9f3c7304f64dacfabd9ee52bdfbcc0bdef68ed8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crane@sha256:6a2a0ab61997e6011d99dad750f627689924e4db86ef63c8a6638ddb408cd2fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crane@sha256:91042605aa14a44be3f38c5758bb42e2590c2d1bd0497dee383f5f9b91b45b90
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crane@sha256:1cacc3aac7c834ef1db6e9dc3499e17aa9d26bff3062a63f01ffc626974627df
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crane@sha256:39bbe6c74d2a427b7805888fa2d9b6f3702ac6cf94ead9b143169c75cd377a7e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crane@sha256:55ab5b8f0318bafb3085ada8cedb46d5f1c5fb3412faeda9414ad6b488815faf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crane@sha256:71a4b64cb38eb9de72ca720f51928ec9cb5586331f2ae1edbb682fc91c6c0a6e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crane@sha256:1eeec1d4b9c3adc5a7d0915c8d1685309c20200981d68ebf348d3387c7c4652b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crane@sha256:d1e610e748f4c2db823a34ef9a369250ec73520284561a5814da2a0fe9514ea1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crane@sha256:b5db1bad748c474d8632e98430194dbb95dd40357042475e4e52edc4813c489a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crane@sha256:83e8f394f3427f0fdbf64605068eda6eeca5cc038f380908e20f373d4c131d0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crane@sha256:7c03081c1d611d74945e81ead5d376da2cf7564b0f9114ee012f6bff186cf322
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crane@sha256:be7e3035c351f3a35df77bc77f6a5abd8c7c592bf249d44127cc3f4d49a0cd47