dhi.io/forklift-api
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.9-debian-fips-dev, 2.12.9-debian13-fips-dev, 2.12.9-fips-dev
sha256:952abf16eca67c876e648d681de9c70ee9390f43f62fcc9f58accb80b6690fb3
Manifest digest:sha256:ff2b227e1c05e84b39eec86d5c4d79006dc183162909f33d8b62e53435369105
Size
67.05 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/forklift-api:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/forklift-api:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/forklift-api@sha256:757cd2da20a5a5ec1605d3d8bbf9131c284cdfdc4f86f99f1ff5bab511ecb26b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/forklift-api@sha256:c7793502d70898fce5e95e704f6e74ffc14c545e9ac9e167158601e5ed82898d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/forklift-api@sha256:9dba680afc669b581b3fab1aa1bd62552af9f8336e6a814ccfd4784a308f7826 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/forklift-api@sha256:f2f850361ee87651b1da7505d47313bbe9668e339e15d149ceb1ee83268d13ba |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/forklift-api@sha256:80ed7970e2f8e301c8874aedfe5029edd7fccc5538461dd77955b879d833b38d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/forklift-api@sha256:eb6e77489ee3334075b71c31eb3206b9d5ad282e6615ba6ee4b148c6fad7c5f4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/forklift-api@sha256:93b14353bbdb6a0d4e3f975fbb45bd6ae7c6f99441d90b0f8d7cae153c47f4dd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/forklift-api@sha256:51812d35f4b9ebe8e906bb82a303c0b6b6696303f689fe3efa627a54a6d036dc |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/forklift-api@sha256:82233af8e52afee018b7c19531d506a68760fb4e9bf163dd8a76fe81a8aff530 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/forklift-api@sha256:1f9393f352ad153e7fb4fc228e8d229ec3a63b7add768b20cae93664b8bad9e3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/forklift-api@sha256:6a8bcdf12f9aa56d5d0a91f9656c3404b54544a00aeaf48d258724f0567974f1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/forklift-api@sha256:121d58877e81d18a90a227ad74b18e4d1cd30c8e8ec70c49af4bd151bb49ae9f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/forklift-api@sha256:d245ef3505f70c2735f11d9cce5712ba5a7d469b35a64564228a4f5144b1dbf9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/forklift-api@sha256:a0d1ce5c7927fc94e9b919434ed7456b8a4f3bdefc56d26d64e8a6a85daafaf3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/forklift-api@sha256:993e356ffd03410aae224166d6ad8e07c10b33767b732c73881c816674d011cc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/forklift-api@sha256:1295f5b17b9a4e1c32d9612fd51896aabe9deace62b4d2d23f4279c4219712e1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/forklift-api@sha256:a0e744faa00c4bb9d8486ef4dd0863c26e404c97acdc837ecc1a3b8c93bafa44 |