Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.23.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.23-debian-fips-dev, 3.23-debian13-fips-dev, 3.23-fips-dev, 3.23.1-debian-fips-dev, 3.23.1-debian13-fips-dev, 3.23.1-fips-dev

Index digest:

sha256:b6a6870dc832ffe9e3b51615ba5b00983794b28cba0ffaad58bc0b5935612564

Manifest digest:

sha256:687d43b26afb0901ef6a51fc9430a143b161c79743ad8bc9b6e6bd655f06c0ee

Size

65.06 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:3d9d824503235b27a643347e8d19c15e850bfa18da86c661ac33a94dbdf2663c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:e9707d69ab96e3137276eaf98cfe0eec9b346402b06ee1beb8cf335c4b282be8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gatekeeper@sha256:3eba4f7adc3c7b870e039fdfa079f8a36e4a8e949601902da508784c1f7e40ec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:871cd637547020f367419451775803c543193f3e0e1c99b955946ea3627aad77
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gatekeeper@sha256:658109a04983b1ffc497b1ef4d71a61cf758fa8a9e914d2c82010c85c6836ba1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:de9065652ff3d219ceab04f642b47556f452a1058345d9cc978cb9f4233ebd9f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:914119feaf844196e6948fde1ac3ab1bbc5a52069108399a2e0f733a67d281b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:680a319a879ab6e0b7aa6f36e2f6fe6562346b9abd7afc80db46c1031cd97160
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:25f8ed0558cda1a8183ed240e494f1fe74e78aa704846dfffe6002128acb8cf2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:5c9ed6e57337abc842533a8ea330ded178e3ae5e62c3bf1461904f1e1200bfb2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:203f2ce67395c59464cb81eaa9db2a0aee23bccdee2f09fbd7e9080c04965fa0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:4fd616e06f9cfe4fafe3c67a13fb5a0d5a3491de61066e1e531faed201e057e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:50391d88fc58b08fea07ec2489104e87b8f456eb8f7ad5292eb729a0df270f28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:c014cdef77f802defa230b7bdee8cd9585a9c1e5e7d8ffb4b86955fbddc92d67
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:5eaa21133decc7cf5b81f2a3b09a0dc666eeb42fc7e40a3b9290b1953f1036cf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:323aa889d120cdb8442bdce3b981704d0ac324d8c30f97e9c60e2914460b33e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:1a03a232693ee79eb08395c7488ac28795d573ebee354a0c06ebe498222988a9