Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.8-debian-dev, 2.12.8-debian13-dev, 2.12.8-dev

Index digest:

sha256:f66b56298f7a949f96354838f718350dcba651ae30c41733f7c9937713657b37

Manifest digest:

sha256:5f76ddfc6abe715c456e3a84a6051bce86e2c5097cf4e0a2aaef24ead994eac4

Size

66.33 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:7a8a3d75f5d3aea6778d0dea89a5de0701493c048a56a66a63dd4d80431a4690
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:d281cd7b83826c1b8b02f0adc1264e03cc20cb3d80cc2e925a1b90042d431d3b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:7b8ef35a42f3d8bc876b023a4b1ef6921aaed70e81141e62d3f5b6bde93d54a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:d46499d038239429f41e8d87169de9cbf2654549fab9f258169599cd192a1f29
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:3e12db0bc535bec2d3760ecfeda1a89315940f65722203980e98836530830fcc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:59e42b15758daa355de13d7d853d4eef544b88deed21a7c374afda0bee09941d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:5f4d2dff9815013abe822d7b933bc0d3da9a0954333cc8b0ded0c4b302f9b54e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:7d3b4777ef1e1902a47e17b5b4315d3a31832a2b57231a07e02216b92caea192
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:35ba4ed878f1cacd3a43e9a097040015bf2e0070df16f6373d2775f145a6136b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:03c85094ef608a6f0d0d3cced1f4383341d1c41701664ae6ca2de74d20cf1264
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:f4a05271fdb8ea10ac146a16add4725109230fad134d8716d3cc463af14456e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:c33a30b9a6fdcb186edfc51b1708b116368d7d6bea3702bc778321dc3a4d8af5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:c8f3ea5fd3d79f15b5cbb9f5c7002881e846f89bdc5a36832cfa74fc6276fcf9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:54430579c0962fc17e80584295be0b6c93af3b65c7394fbe2a5ac7584980aee0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:275bea81af3f42eb695f4ba139ab91198609203363762b077d1d588f3969c80c