Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.22-debian-dev, 3.22-debian13-dev, 3.22-dev, 3.22.2-debian-dev, 3.22.2-debian13-dev, 3.22.2-dev

Index digest:

sha256:1d5835d799f5bd3ff784a687e51a6277a021f9366db6db08aa861576b48e0ea6

Manifest digest:

sha256:6d105e49e3860f5f0515f891c747c96c47c02b076db46697326e9850f1272f47

Size

63.41 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:0ceaa44526a9dc976958bc934017a99145bb5cd7a77f0c85dc972fabb57a4ba5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:d723a7dbae84f597b0567ff756f9616b845e42e9edda7c656b2edf8fd77fdd9a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:5e00a8bb99a1aab7042ea64de247780abb4cfecc844ab1bae852ffa1227981f9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:cd2828e126d77470e78e43808697877ad57d17ead77de79ebb5e271687a9050d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:b48a644f66307188d9bacae2e58cda60f60e884c235d2381a6d6673a409874a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:c521ccdc79e7e12d27becd82f299ec9f55908fdf43b59a2895126afc5554cb5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:0a5fdd5d4686eabd0a8675bb67a0126e12c2ecc0859c76e32933b0112d72f16b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:4b70ef49f5be214da1324d15cd098b110d1ca8daec301cb1533be775d78cf09f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:e4f63f7808a590ac1de58d2e4e1b780e1b9d09f985f8d06b616697826778968c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:dda3e5b10964c441d3e808c7bf9005503968690a667ec04920dff58a2fe9e2cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:e0a416fc71f4fcab52c8f3923720d8c6210d7e659dc8a929c29633a2432229d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:26909f209916ed949c589e83b25b85691a1e2ee03bdef2987e320c6a695b6ef8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:0e0dc3cfa6dd98b70fd5eb971e461f45b5e1d7b4f6ce3ad4bd18e5536f2ba5d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:16402ae0a38616bf5396ceff358996780691f68702fab810f66ca3ebfa701963
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:fd7f68dfdb43f71340028ade3650931c2750301b80954590fc3d6172e0a91c9f