Sign inSign up
Forklift Validation

dhi.io/forklift-validation

Forklift Validation 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.12-alpine, 2.12-alpine3.24, 2.12.9-alpine, 2.12.9-alpine3.24

Index digest:

sha256:9521513dc411ce8fc4384050454901170f15bfcb31a79d732597cc60289357ca

Manifest digest:

sha256:2e27f833834fe1db95d9d5a9532674db50d3c9f168c2968d6afefde92202e459

Size

14.43 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-validation:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-validation:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-validation@sha256:622c9a51b52096da19d292d0c5eeee74616a32d03626ba220d44884e22df5738
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-validation@sha256:a6661c15b6dee72482ca859e45a18fb47c1aa648700c85cd92ef3f09232b269d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-validation@sha256:cd74bf191cecaa8f2c0271b3aeb5888590612e2dd64382b90a8e4fd6263f82f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-validation@sha256:33f992d6eae5bead703d4b1d0878c942e8fbff06e9ecc7a912e8dff7ed05aa2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-validation@sha256:f4a72083abc5830e87805cf4641a4345c500430f0c897ab1c595d2e7888fb0c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-validation@sha256:c41dc6d1bbd8f881c763fc53916222cf5a8b4aa41d9f8a6e57f03be5e7b54a1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-validation@sha256:55ea19a14d8567c94ee5a7adc031b929c8c69eb62454f9eefe336cfcc76d0f2f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-validation@sha256:6ead35c953eee1c44c4abc61a650628c7e932c1ac7ae7905b2de042ed84e0f6a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-validation@sha256:f9014ff0f0a363844a9474f113543f8fe5656346c51d70f4acac106532978dc7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-validation@sha256:c1e14213b7ed3feea9957f59ca71dc9e9afccce996ef4e0629534ade1e41351e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-validation@sha256:438c79b592c8a8350f44dcd000ab65e901b44580f36fea6c530cc59dd8c53da6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-validation@sha256:932e4bd7d4fb42f89fee80deb2a516e2048ae6becbd66c5d952f354930bb4b24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-validation@sha256:f35d487f35bd49b0586c32304e82ce9a78fa13a06edcb5c6a38aeea37d8a30d2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-validation@sha256:82863cb3dd5f71cab2788df75e487a32d8f6a62dac15214c9189fd4d25cf432f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-validation@sha256:790a586d1d978213357354e64bb46eb5c83131f38582a460420de7a1f452e0a8