Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.22-debian-fips-dev, 3.22-debian13-fips-dev, 3.22-fips-dev, 3.22.2-debian-fips-dev, 3.22.2-debian13-fips-dev, 3.22.2-fips-dev

Index digest:

sha256:d6ad06a8573467bc9a57269899be8fd2c842bcd2b753fb8e97ed08036720af00

Manifest digest:

sha256:bdf9a90b21d47db17917a720ece181e4e80c7afe7412eb4706db79fe137afc8a

Size

64.43 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:42d56b1e115c34f621ce4a8ea226f75f71ebf12fd2f637f05d1029e1abf957aa
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:d9220b2d0bfd2b1e591da2ae9102f9f0b25e49fd06b4bf6290fa431215605bd6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gatekeeper@sha256:b0d736f87f24820177f40503c3c7d976aa7311e15480a24f621f137a2a3b3a3e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:576387d0220e03f00335765f521a2f85f3c47e3e7c2ef4c71ba9ea7cb02b119e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gatekeeper@sha256:f95f31a4b52483f67c29d37cd22cf32494996b1245aa245e5c61f03e2eea18a1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:31fab267fea64c1eec36923702e3fadd2326c412efcd104bdfdd52953451d192
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:91072bbd658428085106d1ca0140d2f66f754338c06561c22c8805d82bcae72e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:537710b1410176c533cf4cfd0be1e236766d49720aca89d93cd272aa070ef9a2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:5f03c26d256c5e0b27e20d66cfed35b92f3eb7b144166bd1c0992d345f6726ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:a05acc1b89c1718d23c4fbd59ef5ac889a0aac1aca4f8d83443affcf8a33aa3e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:8dd061b8b4d53c0d5c955dd35cd90fa9078a8c0a0bbfabf25176fa5cfdc02129
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:df11a55a291d5cdf8672b064c20bf0b3494de193a7e4ad5cec97a716d39dbb09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:96843ff500fbf62bef3ce4c43a7e7a7df258c8a8629d0c27b8b752de220357ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:b8059cd88a7501ff10ccfe22df45db28ca77ec11708b340f89e35dbc6e098a20
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:7587fc473becb9687beffbb46c875eeb0c337c368bc5dfde9df812dac8812ccf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:67003fb56d24660e45858d9171841c3f2aa30abeda1f50ca84d1f6b4e241bdf9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:52cc009b5107b8c55cce2af76eb2cfe35f11a0f6a141d1a053fa749f0aefca4a