Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.9-debian-fips-dev, 2.12.9-debian13-fips-dev, 2.12.9-fips-dev

Index digest:

sha256:952abf16eca67c876e648d681de9c70ee9390f43f62fcc9f58accb80b6690fb3

Manifest digest:

sha256:ff2b227e1c05e84b39eec86d5c4d79006dc183162909f33d8b62e53435369105

Size

67.05 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:757cd2da20a5a5ec1605d3d8bbf9131c284cdfdc4f86f99f1ff5bab511ecb26b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:2b44cc14b5aedcba6980af12de64afebba379ad4c06bb5aae17ef193f06cab3c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/forklift-api@sha256:9dba680afc669b581b3fab1aa1bd62552af9f8336e6a814ccfd4784a308f7826
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:f0220b6fe4b519721999881bbc722e7c7814ec795836fea96900e115a912a6ac
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/forklift-api@sha256:1ecd517d9c31a45cf294781efaee14a61e3442db51da60fd13210af2d2a74f53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:6ff149812ea80f5fdd3cd650e70e4d9c318bca4d948c786fa4f3208ef7893600
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:5085efe8c82b6da54c26342a13f1659fc0a830f9dd92132d4592c47d35527961
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:51812d35f4b9ebe8e906bb82a303c0b6b6696303f689fe3efa627a54a6d036dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:82233af8e52afee018b7c19531d506a68760fb4e9bf163dd8a76fe81a8aff530
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:1f9393f352ad153e7fb4fc228e8d229ec3a63b7add768b20cae93664b8bad9e3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:6b16074b595dd06023b99d296f376eb60db5810bad708c7ad1c4fa38f679276a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:2b3314aad1fab171ec1fcc576dde38098f45a67faaaeb184a65c3911116270a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:779a96a555508743d7862e4dcc90848951b46347083ba9a78b214af25df303a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:a0d1ce5c7927fc94e9b919434ed7456b8a4f3bdefc56d26d64e8a6a85daafaf3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:993e356ffd03410aae224166d6ad8e07c10b33767b732c73881c816674d011cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:1295f5b17b9a4e1c32d9612fd51896aabe9deace62b4d2d23f4279c4219712e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:a0e744faa00c4bb9d8486ef4dd0863c26e404c97acdc837ecc1a3b8c93bafa44