Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.23.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.23-debian-dev, 3.23-debian13-dev, 3.23-dev, 3.23.1-debian-dev, 3.23.1-debian13-dev, 3.23.1-dev

Index digest:

sha256:76702524fdd5c263d72eccebcff0b60f06e7d76838f761ada6b529c6dc60977e

Manifest digest:

sha256:05989ff9b84ba84b3c9ab2d78eecd437d3c32e845a667e9f06e08c65e2257bf1

Size

64.02 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:b391033d06f38eedc050150af34e8bebfb19c8e0d49f8bd7a406451571ef19af
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:13ea0a489eb83cff2e6c0e6ed01b722d8f1e1c404939a59d2fff0c9f7788960d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:082a9b9c55d7ce47c89eb3a16cee1bed04bb8a18b7bbc73e2506fd9a6f79a974
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:9c2cdb4e41f5ca853bf7c9bf3f563aa9766614ad766a7f906bfb191a870a237d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:69120236d08ef2c4b0e3c6f5bbbac41e89e862a69fb861c805a106d23ea268a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:7fadc92227560f2609a6c5a776774701dd58153f0d1584e40b54eb5e3c79c319
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:b2beef018d6b0ae152231ce8128ceac752d6e7a7f17cbb6ee3395ba0e8c9ab18
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:0d4ef6496d154f5ab0286e88c350e1e432e1365cc405b6ec027e14030c9be94c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:1e07b9c6fce8912384f222c4bdfa65ab1b9ecad432f52da4b1176026db8fed15
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:7f4aa4981678acbd12b12cf7fb25a9393505447d35f024fd9886b9b1c0328b8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:67d11bb56a6242217ca41c94211a9ede92fbcc5cff05d3411cba670e678cf112
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:37d8084a68ba4fb03aabb3a054aa3055a72aed1bdf0f7f0824f229c914beab8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:2ddd2070d02eeb6a334dec35814fca085c83e2d16ae9ff40cc1ab41087922fce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:edc02a4e20e765306794ab30ffb5395ca45be34bf97e1a28829b3a419eab9382
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:8554bbe4447cc41e5151d98d85611850402b0373c762947836508eea503b3977