Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.22-debian-dev, 3.22-debian13-dev, 3.22-dev, 3.22.2-debian-dev, 3.22.2-debian13-dev, 3.22.2-dev

Index digest:

sha256:cbe62a2bc8d79998e9a8fa9e60da924ec28df5ca55ea39d4d746b8cf58da48af

Manifest digest:

sha256:9fe9ff1f22de3565317a0f451446784e7c3178bc20b31cdaf2fcb4bb25c86117

Size

63.73 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:f927919b8410ab9dd32fecc09f480c2cbf460241343b029e72074fde137939c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:63195e5b6a27a148d0e558fa60e10d0fe38ff80665b663f27f007ae0c2c2bda9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:b755f380718d5401c46a4abd081f396991ef42d883f9567c236d0f067ec4e574
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:fb1d1d76552dd256a55939a0ca5670d75891c6cfaf035ccdb86ac4a55d81cfd5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:15536e0a1fdade9d8bf378457190b0083bb1cb23e582c2d39c6ee9fd0582d114
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:07d663d34ad50c671235bd5cafb28b0aec4b643992c841e8b73215bf4e7d1c9d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:08ccdf1b113450de3460db0971f66c2872c954b13c5736155da7d870eff1b14e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:6ca6eedd06ee811cc1c32cbc31524dcc8f6c4d7c35ee74a6ce3b46f14ada7d97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:78fe7bfd31442b3485b208e85bfd1961866ef6d9d7b31114dbd501766dae414e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:aa05f25776b2c1938a8e71fb91e49521c64e7be6f6f1e24d820382c7a2a0d066
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:5a1c67ab6649082dc3bea1b78fa1d4bce0a01986f139800825ef3a28a5f0e99a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:80163c99f56a97361d94bcb00735913aee96151ef3abd6469be232ffd95148c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:20764c87ae38efffda2bc1e2f561fb524d307806d3623908d4a6d9c08352467f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:c93d6afef543fa011dc43797094fac8e94026d30b69097898eded60e30f11111
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:4c37455bd9789468c6321f72d8d8f648ef0ccafa91179dfba7d66194508a9614