Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x

CIS
linux/amd64
debian 13
Tags:

3.22, 3.22-debian, 3.22-debian13, 3.22.2, 3.22.2-debian, 3.22.2-debian13

Index digest:

sha256:006ebe6d598592f7adf78f5457d99c0a60b4e881c2a5c0a4caac6a1c8ea96375

Manifest digest:

sha256:9649b9c9ac6fbea3071f5a37d1149d243fa6acb47a8d390971b858ddb0c5e553

Size

20.94 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:b11df2be7699ae4284fbb0b1ee3429fd998b7a3590ca4394aaf1523e9a6d9790
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:cd1af4ec55f1067efa795d6c9301a989df49bd6cf79f5d95a76603fd756c56f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:731bb0b2ab71e487d39a32e23e68591e18a75597214e3f007332324545268f56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:738ccf8a7f64097a65b59b401b7b734b1f46b788969fb10c00c2e9f76bfd8c69
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:9af488bc89c269af5edcb0810aeae59cb68a842b7be67a1ce76d375d73c5a32d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:2bea48e64403070939a545198819290ea1d7a4ab69f781634d82a406c0a5940b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:937f6ac3333ad8fded95a7c7cd88b802031a356ffdeabe26cfdd1d51f8ce95c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:ff1c5857743bd59511558aa1ede213c69b54b75c2f2d4edea662ab0efc429d0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:419de1894bc1348b12c0e5a0e551b09c212917ee0f3fe78e01e640a0f753fa4c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:c097b0e482ac2566455feeab5620b348d9e3aeccc66ca1c07f83f17769dd7283
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:c09eb763cc75e63ee3c72ec526f6956a0d66dd524d7eb8b27def8a92030e568e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:058dbd7f3acdd445b8df99690a0805f2d96ff8095abdc723fd805b918f4320b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:d238f05ddb4289787f95378df8b04348a326656f30eaebedbbc78a143cfc45c3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:89175168ec71b9a7877bf6de0410f51931010fc7d160c8dd1329e21c22ec6fce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:2c128a93030cd8419055d1dcc7db8e25e4757e5a1a0a2e81b26e693afddbced3