Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.2.x

CIS
linux/amd64
debian 13
Tags:

2.2, 2.2-debian, 2.2-debian13, 2.2.6, 2.2.6-debian, 2.2.6-debian13

Index digest:

sha256:77924eda1167d7353e86fce2570ed86e9b7af2c03b7fb863f29d552e0e6d58cd

Manifest digest:

sha256:edb0f18098f26f61739c078fdb642ef1aeac74992e583fd304df5d534b9aae0f

Size

26.23 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:d110b633f6f6d9dd3fa0f5858aea95c2286c147c2c0bd9e816f2d415504f28f1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:b81a107b8bf6ffaba810436ca2374b2cbef6c3ec57beeb6df209f0bed981060a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:50da7565c42eb6f6bc59f90131732b68133bc4080cfcae10bd3abb6e7dcc23a4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:48f3c173cc2f344e5d0ac9d01650ac3f177897d300217b2937fabc77d0900664
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:406b5d212267544f0b1b52d309067bfc0314c111ed6d6ea40ef7389ebb9f142a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:f65d8dfaeb1f2688967546d453f4c5114c5a154c3ded9ce1356666471081ecfe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:ba30addd7356b297a7959ba698178e7cf770548a253b1a5b60c788cabccdac37
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:c1794eb50e466741dc164980ff6940455c8da97a3d2b99cb4d52d695f177a932
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:ae35020eb3195d5bbe29ede3bc343779cdd15fb02c10ee3ed2f61471971c5558
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:83daffe758f2115fd189ef186b76d2f65aaaff2ead1f150ca96766379a0a22af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:95b788f9193a8ecbd74a490d4eb7ed5c45b10c9ac96240baeed5921264c9938a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:560d18528ed3621d75341e294febeeb881bd10a65e6922e59923cf924712ec77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:484e082ebe34fc3beca3f52f111d785566f46a318d16904a77fb5e98350e13e9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:c9f0b72f00070adb0c1230719db3b10cc776a564c214fd93281a8c8ae253511e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:212085f72dcad029f7fd38d6ed97bd0c0d1e7d208ea1cdcacf9f1bcbea36a6f8