dhi.io/forklift-must-gather
2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.9-debian-dev, 2.12.9-debian13-dev, 2.12.9-dev
sha256:5d20d4ab057e5cf8be7ec02532e9fce464562be4a18e1486a98b896abd8b74f7
Manifest digest:sha256:39f44294c25b0af3e0dbdb3c9f98dc0aca1df4a153f9c419b231810ea1f7bc6f
Size
79.59 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/forklift-must-gather:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/forklift-must-gather:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/forklift-must-gather@sha256:8b11a6dd3454f7d18c5fc4431c738c6e7df278ada13c396519fe8c98a8f84b16 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/forklift-must-gather@sha256:889785eea83b98fc34a28471bc9080f3d2d4867ebd4817a5cb26ce533b60a51b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/forklift-must-gather@sha256:308de4b8ded7729d215f646f38e9ea2bedbc861460787140248399bd0935898b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/forklift-must-gather@sha256:f0a3b1e2743088e31c2b7917d736aa0775d7202524c40d0ac07bbf10192a22a3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/forklift-must-gather@sha256:5196802f325872c9db6de9215989e2681b2ccdcb6163c6df544f9c7f9ac842de |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/forklift-must-gather@sha256:50ebf20140329471ac8d3bbc2be5e9fb410ce9ec53b6d9a81cec9fa350583f84 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/forklift-must-gather@sha256:faf3c8078ebf10dd26703dbd0f4682e0736a37a3a14b420edba951c12659eba6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/forklift-must-gather@sha256:4af3fe51a36b37d111af10bcc7b739360216a0b07ae7dc94ce6eb8db120636bd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/forklift-must-gather@sha256:5b4c8c0e8987cb9e817d955b7295d3d776d50a3589af11a440d44716191b9f8e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/forklift-must-gather@sha256:b88dd728e5ab61cde10614052c91ea8e612d837c28cd8fce0f21ec030dd25dfa |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/forklift-must-gather@sha256:1298fd048586068c76c1c6183be172c32e71efb3b1c096e6420e6bbcc755aa82 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/forklift-must-gather@sha256:a1e472d06bd1b0458817ccf2aadac7d0996b3208d63eda516762ce761993c871 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/forklift-must-gather@sha256:3db7dad681edf2d3b8bc3d25bffed4fb80a4767dc7ed0e0a054dbcdea1ee2306 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/forklift-must-gather@sha256:6e324c9a6f140588cf3e25aac2ba46501de179562879ca18d46269374d8fd399 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/forklift-must-gather@sha256:1b8d811023a4a33effd2545a0fc24c75e78762d5a3d045e33d78d092c4fdb314 |