Sign inSign up
Forklift OpenStack Populator

dhi.io/openstack-populator

Forklift OpenStack Populator 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.12-alpine, 2.12-alpine3.24, 2.12.9-alpine, 2.12.9-alpine3.24

Index digest:

sha256:5fd5297b72b39d233b246142823f832db9025a1efdbb3e8dedca2401b070f8d1

Manifest digest:

sha256:f31e504c43c3070014f3123b72250f335dfc3b68bf4c20d333728ac7e9ab55bf

Size

11.04 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openstack-populator:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openstack-populator:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openstack-populator@sha256:94d96a50b32dc7b0c2e8da6a880e3e72cc35d24f8fdcc0662a71c0ac877d0570
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openstack-populator@sha256:45d492eb563e0ada2d708f17aa92346d0050dcf388a423f9588fb849be433c1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openstack-populator@sha256:b206addab016fcc862b2b9a79a1a64bd8114e1ed84a541a19b9182526bfe0457
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openstack-populator@sha256:899e39d23906de2c4e2ca9aebacb4bea9ca00e35dfab8da45913f09661bad265
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openstack-populator@sha256:f3dcb555b8c1b82809c374d74984a854cbd1c3c945c5477c3769815b784d7bb3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openstack-populator@sha256:21c0178451eb0ca06fde6077b4978235ca25de684fca8f3b63743bf041170195
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openstack-populator@sha256:fbba4384fa99c8548d8de1b13aa1f5df311e69f2cb352907c22751bd419ac6e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openstack-populator@sha256:3b4970e72125e88906ad712e0f71983881fb8dc1225132bad0233746a90a5062
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openstack-populator@sha256:b8f963ecb207ea2c2718d1048cd067ba9b2d87af0b717f7b78ba717d8e66f807
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openstack-populator@sha256:81bc034a9c323ddf3ac4c1a9c9ff5c21d515cf92683e255528eb943c09b33f50
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openstack-populator@sha256:456882b91828b74fd7b8caa0a776fe8b36c285507b1e19ce71fbccc6815f9ceb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openstack-populator@sha256:dc3f9eb97adbb0243e785849514575a6b9ef75cd1d2d8ecb427a9499600af096
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openstack-populator@sha256:a42344e88253dbe97083a66c6f01d1b96a002fae4caff79fc75fa741900ca8b2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openstack-populator@sha256:57b9986f2814424e4d39ae3f5edf4fe3d871147c292a768cd53856007f7dbfce