Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.8-debian-dev, 2.12.8-debian13-dev, 2.12.8-dev

Index digest:

sha256:9d07cae674e48d5bf2f0081a8248814868763f8bbe5a630c7e5193827a303995

Manifest digest:

sha256:89aaecf15fa19fe935251f42b632d7be62835fe8f00c6b8023ca4a846688439f

Size

66.33 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:21d04a5ddf1b4e6b97fee8a30878c9542b7dcb4e90b7905bec96c8032ef6404d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:3e9bef60d24e79095ee66994dc4c877abad1de843a11ac5750c06a5354e5a32d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:6cfed6ba22a5b7899b43e21ee03c75a72011c68782c237bd5949c11e7a01df1b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:db5eb1d5995459be054d2c595dbd47224b1fcc7bc1b3bd545ca3941bab5a6ab0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:c5b75f7a40eb6943a4d2b0247162719def24bb7c719320e8f58eb3f1998dd8f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:7750a08762337fb9d1d22b8f791ac8572e84507f03dfd3275058354dbc1e98b1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:6546857b34c722efd9edcfde47cd48e7a1c1f626320890fc43e34023ae68028e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:7e4c0ace9a2f922c50205b8efe060cfb3e592cb468c1d0e67344e491a983c95e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:900fdf251cbd51a25d8e1f295ef3e8c18b7286ae8400d61ad25b82200c15fe18
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:9f0ef482228c2c91e2849978b232e5885b2a353cc7fd1ff69cb8ac05c8bb5068
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:cab209299a3bfd962aa908f4bfa80de0befc55d22e139e3ba8f7070f8ab4757f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:82d5bc0e5735cf9d9c5516a0eb1d230f766e92d54f27c5193bff7cc94b81820c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:5d60de4761bb6480b0cf498e292ea3920054231d22c524a834be7cce0287779f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:48f658086198ad92f967d9941c426503b67b2c331a30a7fff7154b690a4a47db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:6b33049c67c4876ad8fb58a2cbe8a38eb9c3df257324c90b9ab34d3bbfe48913