dhi.io/crossplane
2.3, 2.3-debian, 2.3-debian13, 2.3.6, 2.3.6-debian, 2.3.6-debian13
sha256:da5498d8b6ac69f2415c5387d61e2e5d933400710d1c841d434e472081031a3d
Manifest digest:sha256:c11caa8d94400fb32c34aca00853b2a2ff140969c751305bcfa6d66459bca00b
Size
26.32 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/crossplane:2.32. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/crossplane:2.3 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/crossplane@sha256:faa3368d5e34f82d91b602f6622497614152adcde1b0749d5a44bffd2a7489e9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/crossplane@sha256:a588be1a37be2e01629ff2dee6adb4219adbce452a486ee9bf6691514dd78ccc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/crossplane@sha256:7272050868504e04ff5bb860cfef9522cfbe08f724917b6516e308f0b1d75396 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/crossplane@sha256:7b3887afee42ccc6cd915752146361bf35c30c852f167c53b8ff92076bfea008 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/crossplane@sha256:8b3286d952ab174e931209b990d0e34dd2dd206c1294485b208ff81d84ed1195 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/crossplane@sha256:e7346079e8a5e56e3ea35706b0726369a977bc0c26d490deae5acca5f710d692 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/crossplane@sha256:3e5e41aae935e22b5b14703f283f80b53d17d7a8287b2e691880db4809a20faa |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/crossplane@sha256:1ef295a45f70608dfdb0bc9163db1c3eb4b2a9959378b3478380a5807dd4ebf8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/crossplane@sha256:a99011f3ca53a842510d228581e35c3e25f6366d9b2aef0e3953c20a36b4e4e4 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/crossplane@sha256:61cee3bfd639a064af9b29f403d53ee37406327327bfc97012e69a800b895460 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/crossplane@sha256:b9485839b4019abb100f22822a721dc2e39652a09a046c2171a87223e552405f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/crossplane@sha256:0061be0a3b79478f5aea9580a4691a98f9e9aa776bb67419ccf2f94debe02c6c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/crossplane@sha256:fd9d12ce6bc0e49a3250949c79eedf4a12488d43537aa4e7bce30c9e6afcb7d9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/crossplane@sha256:23335b8922322c3a823f699bcc7ce46fcf46fa45a47d0d0d4e62534378b025ba |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/crossplane@sha256:0e56f56a18f0c936f63c4bb0267aeec866d1a47092a98039b323f1a6f0274752 |