Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.2-debian-fips-dev, 2.2-debian13-fips-dev, 2.2-fips-dev, 2.2.6-debian-fips-dev, 2.2.6-debian13-fips-dev, 2.2.6-fips-dev

Index digest:

sha256:cb9889cbdc091ff45c3db02e0e8ca7a27e86df1975bc28d49cff89d363bcbbb8

Manifest digest:

sha256:2d548c29555a1c64f9f79998c95a7b939ce3ed8306c848783a0da2ee3243a08f

Size

60.13 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:1bbd850e2148e98333154f1f52a0409cb73322a0ec1e4b79c9464d6df5d12651
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:cd5fa7c3a77b7bdfac49b847d1a61ace0634691e5eb2943d75f98ff7ffd04550
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/crossplane@sha256:99ba105a6c3a651ae15e1b64af347aaf77245c0b5d96afa3aa4230fb252f6ea5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:cf80deed53e695c1db8f8f4b1cea4f60a909c73a21e693a112239d78e0909abb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/crossplane@sha256:ddb1059d2f2a7500494d86beeeae1f70fd27f64a1ea4b691b46c1c74998254ad
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:0d7b8b30d6f637abe04709fc345202d0c07af5c9070ce8d302499913d22f591f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:fdd01376ff38110c124b8b3fa34857ad12eacb4c70e45e5e6ca96dee1e7e5294
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:606214bda58c7c05ffddb0fa1d0ff04853ebd544aa650832b5a2de58a03cc3ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:bfaeab4fc73919ce24bc353ce0de47e8e0c95f512ca2a33fea0a5ed9b1bb54da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:72b747f7a917a3bee2a1b29c1b37620d2ff247026fa1959567db8ea0ed6fc86c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:5b8cb72d9e487a686b51c60e99540d82ad403950a6a487f5479b1564a3b8f71a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:d2e123685ce8382c472a7e48fde2fb7311b9c6e4fc29788c6a493bc99722d442
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:8b5e3f4113293f35abaeb65d1035603a050c3134a2bc1e14c895d6f28c00a102
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:6318ef0e45f9e69a7255f5c253b93e763db81bb63cd509bda772f1b34ea1c00f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:daeee740a287ed127c76a2ddee18a31ba2562fa14012882f541bc3a9e5e86697
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:acd8ab15f689bfd9d6b43f5c2135a402809b44468d7b4bfa2c089a9c9b2eb106
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:61954836d0441718fd1b81d2bd9353e94456dcafb6129e82dc209050443e9fff