Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.22-debian-fips, 3.22-debian13-fips, 3.22-fips, 3.22.2-debian-fips, 3.22.2-debian13-fips, 3.22.2-fips

Index digest:

sha256:7a3088577ee9159fdee22506834dc23cbac6d6b11b874cf76cf4d83bb4d58b5a

Manifest digest:

sha256:58e13975b5bf1c326c40cdb2e2ecb678a71b453b7d0521a5677e901366596000

Size

29.29 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:bee82e22141caac9e032e29feee4164c0b41666ec38ee66f87b1fa59511e91be
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:29edb1b9c0949156fc02d34fc0448160df9ed2ccddc676fe0912b3f3cbce3e52
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gatekeeper@sha256:42d470eb1ecfb71d01feb80858b1f55fa8630fc2e2ab74edf0e79d80f6b5a218
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:cc9a9a51a749e017e71a2657914d122327e072850e8f639d88369728efbcc682
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gatekeeper@sha256:6de5e14c79626f3208af75df679e968b0199ffb30b8f9cd40aa63534a6123162
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:b1dbec6866e3fb1880f02146db3079f8078617550a5d9c0c32685fcabc26fdd3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:84de923b935abd2e82226048c4d86b8bd67fe1f1166989fd7cc8ec469b5a06f5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:6476e1203236fe01f2445dfa192656d24115e52de4b11313b9eac30ada764d51
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:8d7eb82ad507e0e7fb9dee45a60032e1702c722ca6dc07688d2bb33cdf5664e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:82508fcc94d4e672ad9cb7926e4b071f07176c31637edeaacfa53a95c7d8c3e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:7ae07f16bedb6ac709c997931197c08b62da92ae39d8d78ab24ffcaded83a58e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:b32f88c93a991c617801a726263fe1bc8d010eba5f78d9a0c612ae3bc7450e00
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:d8e63ff37b5e4ac418b848c79868a7c371813e5f876fe4e6fadfb0ca52449697
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:c11e77b5eea0607c8b8d6e2e5c1c130e601acf064599610adfd6c8b14c301421
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:6377a3a1e8020e62c2ff645f51a287aa74aec511ff0d2d16df53c8d4c97b048f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:1095e16589f9ddd15db6fd005041ed895768bb3520076028775469317c320ea4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:c706f9c9e0698a8d1865c97116178e7f4d86503774016951bb00f47963b9abb3