dhi.io/forklift-operator
2-debian-fips, 2-debian13-fips, 2-fips, 2.12-debian-fips, 2.12-debian13-fips, 2.12-fips, 2.12.8-debian-fips, 2.12.8-debian13-fips, 2.12.8-fips
sha256:766296379dda68aae19c4253bb2ce406b761f2980cc38162be5d8d9fb166abdd
Manifest digest:sha256:89e2c54c1104a4483c7eb08a9bbb750e2e9d3ac2348ce438bfffa949e39ced6b
Size
46.02 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/forklift-operator:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/forklift-operator:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/forklift-operator@sha256:42222f0d454e40c0584e539f066aac996799aec733a0fe3b645249738adec3a4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/forklift-operator@sha256:ba871d0bfc31d7f14e0f59bff63ecdaf285704d5c2fcc0b55351ef4c030835e1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/forklift-operator@sha256:e7d8fec0bfc7f073e0154c2dd3b781c1146ddc33d501e8d8feea18411a64c6aa |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/forklift-operator@sha256:719b24e3ff87008b0be30e2a38fd5df2232b1e9e3eba58e498b357dc988011fc |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/forklift-operator@sha256:6542618dacdf8aa75bcefb055bf1d37efb2b6ed151c38e700e397751f62f0e22 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/forklift-operator@sha256:fdff6d74ad47b64a7fc6fdf343c6c01ef95d1bfb427f642f55dc66638911b4bc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/forklift-operator@sha256:91f40568e2c7b8b781dbd70ffb1bac6accc1ca34e5b0077a864ef9ae6dc0f5eb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/forklift-operator@sha256:80d6e018038d8541ed5ad0b9e8779c6451b28bc135c8996764fd30427ee16b8d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/forklift-operator@sha256:ea73986c5fd8c1c91259e9ac6fe8c43a40672abaf0743a2efca06b2c07eefa58 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/forklift-operator@sha256:c956e57fa4dcc809edfa8a49a5dd186cb8d1f1fa65d26b3b7f78a84919df1b90 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/forklift-operator@sha256:bb9a22f70bb2181c17196d0070f3f008a1e5db1b51d0a4956f373f048485a97a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/forklift-operator@sha256:ed0eaaebef63a6111138b19e926ab9c82e60ef3c5a758077616015cf877ec38c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/forklift-operator@sha256:75080053f2417c6f12837b2ce6fbc8b62bbe898e51c94b24d34a09486c4e4356 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/forklift-operator@sha256:0e08173e7b821c5055ce782fa41e0e3e6a55d78ddeef5b7f0f03a1de426f5183 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/forklift-operator@sha256:e2263cbef8c2805d8580863346bb76c94d1892445b6391da653d0e996e55c225 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/forklift-operator@sha256:90d054f0568a3bac7093a675c88c2b1140792150acd80ea0fb672a2ae92234cc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/forklift-operator@sha256:8a43dfb8cd5dec6eb1c77fdd8a9f4e39a265248c12c24c8792ff50c83ed67da6 |