Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.0-debian-fips-dev, 2.0-debian13-fips-dev, 2.0-fips-dev, 2.0.8-debian-fips-dev, 2.0.8-debian13-fips-dev, 2.0.8-fips-dev

Index digest:

sha256:b5be80712a3cfc5ec2cc684a7fd6d8086858e683e7780d253d1ef47874b3803b

Manifest digest:

sha256:af58ea89788ea833c569ab89dd52703368db124de16107baa272fd08d2e81e81

Size

60.87 MB

Last pushed

10 hours ago

Vulnerabilities

1
1
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:a5ec3b26754096c9c9006b6a104c02dfadf4f14d3f172c86424d73c3975baf8c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:0aad86aaf145186530ef7be6e7c7ad28bfb6bf058d306529f2b171320f5fd743
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:80872dfeee155380f3258d697b28307c64d48b530a4dc7211045b55ded91904d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:c4845e7d65c82595836c18f846c755606165b3d8bcc116172f1ade015ac8d6ba
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:be0d61b34aea607bba8dd65cc1f55a4627e28ef98b32ded3a795f5111c7a7d55
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:21fd6bd116d830e3a0833edc790ad794b8fddb642a98bfd865284bc1cd3bf641
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:fa2527019bd4915d9f0de4cf0d3b8e37136af955beab64d91c58312173d48038
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:693338df1a2c38463f6ebc4e66842a5f2fabb81db6d5f2d0989845e0e5d520bc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:4cf9a690d999a90f524e6de1626df472bb2063356cea44a8f8a03ec8b5b097a4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:6d5b8655e8b51fe86f650086d66d38250aafebdd7db756ea6c2c667c7ab4b37c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:e278d4c75f4e67df19e07cf390328feef7b3e5cfd266f80d7c09e0dafcd92d1f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:278bea47ae0de11ffc1b0feca2d1bd5ac0679ff67321966cb9c4bcb135f826c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:398946bc4739018a82e820b040424e2a585e778036d30e5d527a67af5bfdc16c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:6c0292f23705692ea67daf72543ce33f49c8b5c6e7910edb5ad97a765169c62b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:ad2c086dd16896ff6c2b69dc5dfdafb0d96a2938c93627344e4e0db1723b4d58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:eb66451c23c6685dfdaba414928a4a96c2bee50acd9b85cd7f2885e11b276cf0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:2d85e32002c19dbc02b661a3e022007bb9c1122e44dd2792d3821c718ba41713