Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.9-debian-fips-dev, 2.12.9-debian13-fips-dev, 2.12.9-fips-dev

Index digest:

sha256:d35f0bee66423d063d96c0bf2025f0eea45a16e4c67a76c6e4abf35efda4cccb

Manifest digest:

sha256:d0c1a260d76228a739d7d57005057ad1ca7a8f883d42c499e5ea3b2bff085247

Size

67.07 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:0d87e093340030d2d9a11bf5f736268741fd671440c508a964fb5c09bbb24d94
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:8c6ca25779ca0d979123333169973e4f1ceaf6fbc25eb7b00f269def82d6d697
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/forklift-api@sha256:d5b53523875f28bbbcc74b20378332bbf858bdf1a608eb7ec75e56c9d787a1c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:6738546ec09838648a45f9c5ce328cb862061bf77bbd3545f96be712fa95b9f4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/forklift-api@sha256:316111afff392ba780a820f1d409d4b5af4b52c8a3c681dd764519e48e41e4d8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:83b32b831dc1c453508cc41cc3f084ebb5761d8a8fddb2761cd744c9544b277b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:e82e8d831d40958d2444b9138856292fefcb08bf5974f66a7772b94729ac3132
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:eced9fe92cde3a3d0a2ebeb670ccbdbe9a40894030f5d19c305f43cc19523b5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:a8bc34d38c1206da8736e88c1431eb07f538f008299bfb6ee2dd00740118c0eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:d88bca0601f3d52c5e9c4df4cd2e38a57f944c02713555ca9f2be4129bbf3f1f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:039c30403d6afd7fc8acac12198e9dc966d4db518d85d16a073cfbe0b2b1e8e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:748e9664cefef50c5ef54a75a6ad4c0c82f719969cd2ae39bbb9d6984256f194
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:54aaf4e9ca0206cc629ba11872f564217c0229e485b6d9f00b13cc5c692aa57e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:7ec2f68e37aaaffbfd19ee2b86ebbc1c1f8506b4959122414e6e901b5b3c6518
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:8bee2c967dd9ef7191c8fa83b65e12c4a059566301d644d8d5efc83db3cc7fea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:47d1447900ac3207124ec134e7355e82ef614a037793f2fb58c21ed5eb9a8046
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:6a251f3a0473a41a22cbb25605fe27c1f5f5244c41d150b9bf0f0ef6cd2ef646