Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.10-debian-fips-dev, 2.12.10-debian13-fips-dev, 2.12.10-fips-dev

Index digest:

sha256:44eb6b985f8484d92c5d8a5b2f1eaeabc40be7f730a746348dfc634108fee3c1

Manifest digest:

sha256:7a848c8721ede46cc512cefb262bf266c26b0ec7fd199f27798c825e11577505

Size

67.05 MB

Last pushed

14 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:ca800d31e3ec9ce417ff61d611e8d4109d4f6e2f195e36272b821a1dae20330a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:dc5bf9986c2340eef413f5827194725aa1aab65ad1a5f0f81e1acf35d8aca9bf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/forklift-api@sha256:0d88a49fdc8c1e56b8388ada5bc7a7f5ee84fd35eb2357bf9223ddd17e2a4707
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:0a12264b81d2dcc2c242987c6f58445538cb5b95a8f67cb617f5399919bc77ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/forklift-api@sha256:74b64d9d8219683816396ea6d4c459266560920377ede6103d9498534e5f3cc2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:c2ae2b1077c90d7e286159a2ebac7f7bd6d2ac19c9756da033541df23d80c71b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:06eb8195460583c19e2c9b4ea40a6e0517328113b838db40077150973638cd6b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:900ba9acea1bd095ac54b9378444ac6d9317444b2126887486bd58e0728ca73d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:dd3d2c96b9f0e4e05f5e8f1b34dacfe4be2aed96bddb2c174aa81215145e6bcc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:8a7a6df13b1ea42cb6f5338f8f5b766738d1bebf7857b7fe1742c8de13e52fe4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:6d90e2105b6e9e975a3fc1d1c8d775f89b79e244dab6114e6485aab83003f65f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:cf8adc02032555f10317a69bd944b72fcd823c00126338496a827e3b2ffa1137
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:83e23717b745a5a79c951d517fff72e5ac759ff965037c4753f165c6017848d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:7816657ba2af476c63645c8f9a958d92e422723fdd7c13e8adaa0a4376fa6381
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:b7bc0c66fe1f6ae5d91f980e22c82069c6ef6be1d0c26566e819554dc7c798db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:6882117856c6f1915d5216d3ee905e322af78e72487d294cbc040abffaa568dd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:68949139699f65e097b41d5e081b74f389a00f9e61c1b3723136b5154f4ff8a8