Sign inSign up
Forklift Must-Gather

dhi.io/forklift-must-gather

Forklift Must-Gather 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.10-debian-dev, 2.12.10-debian13-dev, 2.12.10-dev

Index digest:

sha256:8ace6ddc313e6c5b0c1f99fd2e1510439b9391340e7d703885f4fb0d5133eea7

Manifest digest:

sha256:45c5cd72c8fd63bc4aff756c8f940e9554ced533ebf978d5baa4a155e0b03437

Size

79.61 MB

Last pushed

23 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-must-gather:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-must-gather:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-must-gather@sha256:cd0157f481b2c6adddb03e31f5029aae7eb009ea51984dc277819c0c7bdb4c7b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-must-gather@sha256:39120ce66a37f8214617c82ea2c693b864cfe23fe07f075780915fa8069498f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-must-gather@sha256:7b6146d402b5d5eccb15e85ac17eafce22763247948ab4f66a7426c7c817722b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-must-gather@sha256:c38fe50deca554081ff0e251cee3194ad82e403e1a24385feca8ad94743c8a2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-must-gather@sha256:0e4f3a262a50f376099d730e6171f8254a398da7246a6ad546474eb315822d20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-must-gather@sha256:2b473cdebd9077cc099162d88f777229b08d80ebf1d2db27aff4f3909aac396e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-must-gather@sha256:7378371c4ad9a71331737d410260ff4fd2169965d1f82ec6521289ea41cff33e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-must-gather@sha256:959838c403831ba69191e19855c623af404222c2e15c7808b107c0d8e5540862
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-must-gather@sha256:afa202361949b7628fdaf8bae4c42d62500167511ef4b14398af40ded6455802
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-must-gather@sha256:d1522b46a59cbed3b5ea77e88852951d3c99097191b3ef781c12f52c1a63da51
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-must-gather@sha256:b88d12b9145929639c064c0cfd9e43f1f954bcfa09e8e6b8f2e247e7e8b45d58
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-must-gather@sha256:78f3be6dbfbc1028406f1adacb5724dfd7ad71e50bac8b0641206e82e96224ca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-must-gather@sha256:53433069a4c4813e24208b8542789f02afd094e9bd4038a749c9016597889f4f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-must-gather@sha256:0fe73d85f1818b11cf83dc197d1d498c3741b03cad4b6fa064177077b6f74e21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-must-gather@sha256:98f29dfe0dd30a8598fc5f6c6bf67a7ccc2dc7bd2e74eca62cc68a21b97ef63b