Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-fips-dev, 2.2-debian13-fips-dev, 2.2-fips-dev, 2.2.5-debian-fips-dev, 2.2.5-debian13-fips-dev, 2.2.5-fips-dev

Index digest:

sha256:9776683375b84f5fa1cb61e412906971cdc69508a179bf69a42756358c5aadfc

Manifest digest:

sha256:23ca06540b255ce765bbffdbaa2203dcc1df58d237ce5ebe1c87e0ae66f6b92c

Size

60.13 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:3522cc8af44df8e019c35c03da5688211a84007068223413c4190f1bc9eefa36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:6dadb28ebc4a5700d881e6d545b71068ee9cd0c4df4d5ece5a8f4ec67e4c5ace
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:898e4b2878214dfb3f62a907c114d4644a77a88b00162333c5a150440ea1427b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:6f2b8272882a4790f3da5c6612ff4ce3b8b204cbd2275d104a63e05c214c9b23
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:04e6509bb1455db4fb896f3817b8f623309040428d1214bf91559fefa3d56c99
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:f5f3396f9878f872beaad43039a81860bc36ab64395662b922eeab918c9b9688
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:411945c9c4feffba96e2d12da3f76e9c498692d59265ec2d7147d36b0e44a30a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:1dee808f53132f3312454048212eb8b9c1f6723e3cc1b9009e511aadde258829
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:df3434c64149074c1e21dada52e369db94467bfd46b24ac2e558c6c5c4af9ec5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:9a9928a7158875df43e9019da0ca38bdab83323aefae78d9caff092120861841
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:bf9205c4c68705670d2805d6c12e6cea8eedd0445c5bc38712900b6a4a68bff9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:ba26314637082bfaf84119ddfc0f2b63c2a676d37ca09c5e359cf533d70f3a5d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:925fa5505bf078cf6127c8525518ba8048c95882111f4908b4c0edb2aa3de286
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:92a13f35afa450135bc3ba145458be9e8af2ba96212495e8c52283be50fffb0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:a9507f9ca5c421aeb1fc0bc58a331aa1df08f997544f330357034db66ec4a051
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:c2fe90032ee489d4da54d832c345cefdc9ca30dd855fdd0ea7591de1121c6b8f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:d82bfa2f853a4abc7ecff926d1465e495b8b2721daddaf8934afa6e131315535