Sign inSign up
Forklift Must-Gather

dhi.io/forklift-must-gather

Forklift Must-Gather 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.12-debian-dev, 2.12-debian13-dev, 2.12-dev, 2.12.9-debian-dev, 2.12.9-debian13-dev, 2.12.9-dev

Index digest:

sha256:fd23bfac988cfe4fcfbd55d0dc369de80f910c5738384a78a0be8ab763f92e96

Manifest digest:

sha256:eb909a3054d7b229d91e191181f394e6f4304538bb26c96436e8186a8274b05e

Size

79.62 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-must-gather:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-must-gather:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-must-gather@sha256:c6d39b69ea7252faa7f3a56735164817f7e39a9d1a2def4ca855808a7801a329
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-must-gather@sha256:01063bd5d14b9e78e66ce2176aaf871abe08744a9cd9c2d2ee80cb484c654ada
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-must-gather@sha256:ae6d91dc3043beba16370823556e148b6bc4b252d1efdf40f7cce55443d97653
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-must-gather@sha256:7e86ac0a8a17f0bc07b328eed8cda6e1ff104a01b1ba2ba3bc68a7a1b6872c8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-must-gather@sha256:9542f85c75568f85a54f88871a1fa68c47eaf63e95994df2e78f39844c156206
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-must-gather@sha256:6c4d6e057a74fff969bf440a0e47a02d4221690bfe1fafb816e43720f9b31469
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-must-gather@sha256:12b7ecc4530e584d0ad0233242176639cdff97aae33dbf5e9ce04d028df9cab5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-must-gather@sha256:20ad3fb477c0dbcc4439ea4a35a7f72ab52b8efef76883998a741b0ca79f92f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-must-gather@sha256:f5873be901b92285414c7fac5e3c4608380c92b9fca334e7b212cb465d80532f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-must-gather@sha256:290cf45708604d03dfaa29104e40bd98c9e3ccb9f68a233fcee3f63cd6dea1b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-must-gather@sha256:22faad9d505662c1f7935a9fc5d6fb58750eac7e81cca5f0ee0b4217f85d1034
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-must-gather@sha256:b59a723b2286da5e2111cd62aa8a7e91cb80db1a1e7de288f4231ce87adda0fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-must-gather@sha256:b333cd22a25c4cbee11f2adfbf5decbca78409088e08de226671e33aec17cbfc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-must-gather@sha256:fa93b9653cd0f87d79cf464d4c310c676029b9a8b050cb136f81c69b955d899a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-must-gather@sha256:af50492a1bc919eef89c15f2ecd9a4b2afb557fc1aba9bec764f779536fdf997