Sign inSign up
Forklift Must-Gather

dhi.io/forklift-must-gather

Forklift Must-Gather 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.8, 2.12.8-debian, 2.12.8-debian13

Index digest:

sha256:451b1737512b851a224c72e5c5dc66381825f95c0b7f4ec657b8e50a8e493993

Manifest digest:

sha256:a8ce42992277e5105a2cc96d2fcaa1a1737cf39ff02bbc9ab4c54a4e67b62589

Size

38.70 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-must-gather:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-must-gather:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-must-gather@sha256:c726eae8f76765317f7df4ace5f9915527b1afe85d4826c240b391e0af0f2d04
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-must-gather@sha256:19eb304c91fd31dc70bae087283bb094eac8af7534dadc538306d25740d013f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-must-gather@sha256:4d5ff84365655f526402ad538ac816b154d9886e84293125c6d3a1d6c54f23eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-must-gather@sha256:3dd09988aaa6787adfea9450cee826c58ed32ee9741066b48a22cc46d3634317
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-must-gather@sha256:951094524fc7292f9d8ea6a6f677ade6f7d6bb170b89398c3aeb0e0292e92de5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-must-gather@sha256:295666d1598f389bce48d0bd0ea926c4d6228325799a3cf2107cbb92230e13b2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-must-gather@sha256:820ead44b1261920805065385221bdeb444baa35cb90f632cb7c4dc1bac8b1de
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-must-gather@sha256:8b0fe3f0412ab9c082fa59f9323e4e7e36588e118c05092c013a79cb2308eda4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-must-gather@sha256:36f6871ec352ff3a4d7542caff7ceae73ee050319f8a0fad5db33a4939b76969
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-must-gather@sha256:1ec71101c2f95d449a33b2a69431edc14dc5b6e3f056ef6376902c1721eabf10
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-must-gather@sha256:589c52381db561b8f59631a0d5f622c3c8a3ef1266f7d16cd7fd905f6da8eef2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-must-gather@sha256:6f3b152d6aea9bb6cd11af65056d1a08d543dac011c27bd9692ba244b1e1d694
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-must-gather@sha256:ddc3fe5d07b636878ff68d97b79bed44738b9e025ba651f09480a867f89bb128
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-must-gather@sha256:bbf180ba53943155d9e9f2a9fdd3ad200cc46a18379dfa8e9971831e32e3cd18
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-must-gather@sha256:b64f4a3a124ac79b3b3252a170cf46542d4f143e7b354501c36fb7d414e22be3