Sign inSign up
Crossplane

dhi.io/crossplane

Crossplane 2.3.x

CIS
linux/amd64
debian 13
Tags:

2.3, 2.3-debian, 2.3-debian13, 2.3.6, 2.3.6-debian, 2.3.6-debian13

Index digest:

sha256:7288267cc0150192f871caed5656633f228c48f1309e7090b766df6325d20322

Manifest digest:

sha256:3dbd81c4fc12c008c72804c900d3332f34399713c2d264de3054cd959249a8c1

Size

26.32 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/crossplane:2.3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/crossplane:2.3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/crossplane@sha256:f6028e69687cd91d2751d0c6a1236f3bb2133218e7b1436200ca4966c0141f52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/crossplane@sha256:9aa662917acaaf64adddb5e81d2fe2b93d5232cb9d2dcd189788c157908a0305
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/crossplane@sha256:48312f87f5f2fa56bb515d2d1ccfab26f3d9f468a5d8908d7447e989cc25c1e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/crossplane@sha256:ac2f06235c6667b9baf3698739200ebeaf5cf01b1c81575ecdad18acdbdae7d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/crossplane@sha256:0b46df8cdd260b8e29d4c39d36e549af60ecdd3cde4692cf1a1f76cab5167b82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/crossplane@sha256:6689b3a3297f9f4013f487109b19ad0d47c4979642314a57ba44e68097834549
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/crossplane@sha256:443d1b17174e4568f601fd51faac68ca6a954aea3f89e888b74b1a1e4c2547e1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/crossplane@sha256:c6b237723078f26347a542746d29bafec322e108191a00c88dd73c9b8214ca83
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/crossplane@sha256:97c51bb9b684fa239c1fa5ef8b3ab8ee4920fe5cab4388d49a32626ff20dfc38
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/crossplane@sha256:2072a7362318af61ba76ac65f2a4f385d206a53630ed1e57f36400d304da81dc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/crossplane@sha256:300334e9f6e43cf06cdc48e21d4b952d99a7249a0cbc4b7947df75c8c93886e5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/crossplane@sha256:48647a7bde44133568e598301b06081a41c956fcb12de7b4237d8ae27412d8b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/crossplane@sha256:69e0f3db161ae59e70b0e1be5b3883b52a02a9f5e72630ec4a584d0589120609
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/crossplane@sha256:e79370fb18e4936260d015c5f272d1c88107565e28f4dc42ca7c98e7478fa92c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/crossplane@sha256:ee6ed5fa1d51ea7a844d6334c7587676ae01b0ca5c286aef5f8a57d7a8f145ea