Sign inSign up
Forklift Must-Gather

dhi.io/forklift-must-gather

Forklift Must-Gather 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.8-debian-dev, 2.12.8-debian13-dev, 2.12.8-dev

Index digest:

sha256:13c02354b2f600696a9e629838af7dc0233f29928d3a0c23b8320c1a60fe644a

Manifest digest:

sha256:0e658165b46124dc6b19d200f451a721ffcbb3dcb46eb5594a2610cfa3958889

Size

78.33 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-must-gather:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-must-gather:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-must-gather@sha256:f24fcd37c476b6a0fdd53f759c00a43adbcfa903c6466df84e334fc30c84dda6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-must-gather@sha256:eec9452013d55243fb86300294ba544478addda691000d661b42cc9ef8336b1c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-must-gather@sha256:38887f7492acf064bef35e41d9b6b56e95f79d80da21484859c676e7da7244a7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-must-gather@sha256:6d17071343ebd1df0e7040c4478612c29a05276cf2bc3a9b9dd716f7ea29b59c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-must-gather@sha256:49123d2d25b44ac3de6d8dd58c064ca8f394892aaf087a76471bba0f44c859dd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-must-gather@sha256:5a940a50b77208be86bd01c12a5362c420c56633424a0b31eb2ea596c6053268
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-must-gather@sha256:f145d8aa3a494ee27bf88450f39fb8f0cdeb461f177718a6667d04d577693c67
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-must-gather@sha256:31b7b5954d09850da40e41469124ace8edd38423d8f9712d85d0b0d0c3bf3bc0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-must-gather@sha256:0e1911018e3d4fc37faad524b8bb3fdc9acb03164bcc58890e3bcbd3dc77b016
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-must-gather@sha256:984d2ac05e4cdc3ec6010ceaa731c64c805c6e35dd71861c82cc1bcfbd1e6fab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-must-gather@sha256:246d61d62eb2ef6e8653a6816787797c9e333722b9d91ea0ceed413481e80fa2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-must-gather@sha256:884c428681be517bca6758e84cb31df962bc67646cbf362b109740330e1b4603
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-must-gather@sha256:e7af93a432cb7400f238dfbe4536d57353bcb6873ff879685b7e05b370db17bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-must-gather@sha256:7522c86297e05f331da82370f68ed1bbe6652ee92c80c9a8f439e7fc19dd2be0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-must-gather@sha256:052e8277fcfc6aa10282ba09da25289475e3dca48fa46d1b7c175e30a8a21029