Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.10, 2.12.10-debian, 2.12.10-debian13

Index digest:

sha256:9e87056ca002ddad0a80ccd4b88b3d9c5c11ab2b4e21c50a68e68179349f537f

Manifest digest:

sha256:e7847705cea27cb0d5fb987de3f4cf4e796ee1f3f64cd54016a408b3f0064f0b

Size

22.00 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:c5e91c2eb8bb3808d3d3e19057d3c9cd06787f8e06209daa49b237bf5338d548
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:ffd659d467a01d80e14d0ec2ec7583b8ff04bde1d4ceb9cc5a4eddb08bfd1221
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:51a772f1daf9b6eed8911ee62fe3cf04fdd00b88554c47566f616b161e9010b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:344b7c7239c2dc1516f17c723777304c7d5f5f769d976c8c4447e02c9092d8a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:51b1ebe30c759dbfa49e7169e2fbaed34627409cffc7565ac845e5bbfd6d2609
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:778ef43b2327df0eb855f3fa5281d7db634b47d1da956317eab6797e16c1cf44
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:d31a2f60f745a58226ad216c6ec3e27f7f88c714094c2d3267c58f0f5e7bd03d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:645d660f5df5e2215e2c49e8095449809206540fd275098d593f3812913410fd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:1cab8e037a1a2066f55394bebd27e59cc9beacd898fe7366e2c8cd9a6c6507ec
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:b9c8fec746a368f016cc6aea989c24c1dd6435c22fd8dce6a1c8f2c6d11d86e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:ef27dba58ecb932d92c9ab77234de3b1391cd82b4e14c167a1f731b2060dad2e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:b55d0a45cd508ce5004703bd2e5c776ba2e0baf26600d76bb22a92134332425a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:1887b381bde37667d52b33242e018902a71f95a3a892e513ad090f74044a0fd2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:cfea1424b53a2bc8eeb3d4dd2b0bccf526e6d21e139b32cde053f3581b9695a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:7e4352a404f034e46acc48aff1fba58ac20e5cd2bd77a6e00dc4abc5659150dd