Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.23.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.23, 3.23-debian, 3.23-debian13, 3.23.1, 3.23.1-debian, 3.23.1-debian13

Index digest:

sha256:8f01e98acca9c113bbc10ae63723c7c7af5f683ae96b0e1e595de7039359eaac

Manifest digest:

sha256:4c932c9e82f4f971378bd5a1357cda47cc332629832e35b9ab79187c7b6b4d8d

Size

21.42 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:743e39ead03646564b04aaee70ca6b6e5751d811a7d0c9830aaf7f6b56dc8564
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:58bc926006cf3aa7fa426d5cee732dbde182ceb12a3f8763e89cedb6b6c1be92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:e50b75f5844cd1096b68e6b7855889ebf53202eda62fb9aec33659322941c4f4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:b3c1fcad90c4d3e6ad27912157ffae075f0ea829da78a17395224141bc5a661d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:722d37cfbe2aed800ab76da44e7ff3c2a0a1460034f274fec6ad3a9cc993302d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:60ebf5ce715066c7a719c0d04f7fadfd494ddc5ccaeaf1b0d5446bbbfb09b8d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:5e004cf1320aa79bbe811eb37fb5709d8f36a1246c7eb58d73ded4ba0bd44604
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:fb6f3a2e13995d5d2c24e24cc2ae8eca04eb409ccae6ae48616f69881467ecb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:b67ca5f06266f595f39f636aa49584ef81b4899f9cb1bebb9084f1dec1fb5ab9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:e4349dd778c5162320d913f99bb2ec12768dcb0317d3599b0c24e1fc202c6718
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:a4326aa3d079705eaf49fb6ef341851fcd449c38cdfcabdfcf099c8c9c94303d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:8e8a26ccace241ad28cb3213b32574d2ac32808a8b8a9dabfe6c1142f5ffce55
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:e34626f9f969914ed334a1c34f1a004ed4a95d0887b7ae33e464c9213b131d11
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:994dbf1053c02250d38e56ed04308191d9cb91af1eed8bbf8fa896d235fee18e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:d1fa3a0e2d7c8e8f46373fa37ee025771a78d1176826214ae397aa16bd8ec611