Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.8, 2.12.8-debian, 2.12.8-debian13

Index digest:

sha256:9ddef2c3e62469ad8a5e1f53348f079460bfb9a7aa16b8337ba8d502b2352b16

Manifest digest:

sha256:15f2fa9ed4669987f043c28d82ce63f74c2f7c8583dd7d851112eadd730bd76b

Size

22.02 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:c3f73afeac2a7c49edb1092f039a4ebb9abf2d70a52cdb3b6ac23c7ae4519e87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:9b2b32816beb4f949c5bc885d351e1ade486ec5decc84ca8c946d06fddea6668
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:c0ad40dc8b77ad27e477c44e04c9ef3f43a8a6165aa2c5c2363416cee9f317ca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:8d5552b8ed64f432f3fe3aa86447f6e8b82146b0bde497b2e4ea68ffbb86d14b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:7d8852ff2ca7bdf38d09b9dd92964917b7899528dee49805178e0a59967f6859
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:7a2659456cea87fec2877139bf24adb5c331407aca86d1f97a06aaefdde4cab0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:07c6a32cdfcaa8155bb8344406945d13d29e3a4e12a2f9d6475a429a1bcded8d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:0f346cb2d6e164888e495628a72c99945d67429c1cb22243119b44fa02cafcdc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:d6be38070d0cfc565e27e3c5ba9e2e17efbd17ef433234a23f59b908a7ec47a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:696b36aeab1bad591c81e0818df73cc1b7f8af54c664ced1b11e59dd70dc7484
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:1511be3e91d73ef45ae9cba5dfd234dbfef6cea1dd7b0c0e128e6d1a793db90d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:89cdbd67c4a3381f68f1e0fbb79575b83709f15337b80b127fe657c7fc06c705
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:3c56c356fb828ec326f1d03abc9d7b834f851f28fdf6ba32740de36922ed136f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:00e655560921fd2008d5213b42eb75782c5ed54f184aeb672a741a7e6ccaad41
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:b80560fc2d013051a94aa83a64e4b877c5445a1c0152725ffa59e9808549fe09