Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 1.20.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.20-debian-fips-dev, 1.20-debian13-fips-dev, 1.20-fips-dev, 1.20.12-debian-fips-dev, 1.20.12-debian13-fips-dev, 1.20.12-fips-dev

Index digest:

sha256:e4458d4b4f436d9f1f162d4510a4039bc1ad02803c231cdc5af67cb3da4c8f29

Manifest digest:

sha256:3afd502f37c88751c2fbff608cbcb40228f889bc3d060d8074f3f95ff9c63ce5

Size

60.91 MB

Last pushed

19 hours ago

Vulnerabilities

1
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:38e0054b3ef4b2a22d3d5e6cdb1a404db5c2d5f200dc8c256e00516639063139
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:99d405846c9a988247d61fa1c8c9613dfd74a52d0115b7a45e914256b2d4bcdf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:e59a1be87a367014e0ab6d8456c145c66fbeadec07a4f1b2890c2cebb08c6149
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:aa9d594e22cdf7b16ae136c0bd0aa1c9ad4e3bc5224f50b59d7e20d48349737d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:e8479558e8b0f8291353e124d9451ae6dbbe33e488cad021bf90b32ddefae53e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:4f53040d36d5b9a7c85077f9fd315fb5fd032486493926885dc418056d995334
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:639682b31afdb549b2bac9a190f30aa875c00ae1ec70d9f893e378ccdacb8aef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:a7ff1e592dec37d0605822f232384941a371fd5f0f781d77ce06bac524263f44
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:b50e08910c66e59bd76a37463636f9cbf2031e6cddaf2d620e39bf48d0c50982
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:0cd2e3db8c363bbb6199170782f9ff57a624d9b63cee12a04e6bd91989bd67dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:489085e525b3eeb964d058f16154724cd743e37ec092551e7164cbde6d2035b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:85b3a97801eff09c0a0e6e9daba8ced37b79dedc0ae9938f1d3dacbbafdae76a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:3256ae640fa2150a94b8503c113ee3f57aae0cf91a98de6ffda27cdea64062fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:928e7c3f7a60c13156f35f5f7ea7d0750c9e89dfc636b4af0faae976bb98cdac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:aedd4e201479b32a408f94ea45e40077876a11df12b9bc831c5aa27ab4f37494
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:9903f214e9049b068dd46d118624e26c37496cea540499b9e3eb905b3089f2bb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:95e5aff496570dbcc6bf4b2764a3e73045aeaa06e69f688e6ab45afb84435724