Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.23.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.23-debian-fips-dev, 3.23-debian13-fips-dev, 3.23-fips-dev, 3.23.1-debian-fips-dev, 3.23.1-debian13-fips-dev, 3.23.1-fips-dev

Index digest:

sha256:9384022627cc8ba917c9c00190bc50a39159e7b7395a2202a28ed796a9dbd395

Manifest digest:

sha256:eeef59e9715e558affd49c9043677648e13826a0961ab30f3956eb543e7c5780

Size

64.76 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:67ac60717fa607ea6d424112b4402269a954ef7230c22d2be58f7cf47d704810
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:5f7a9d8f72ef36d9906c055b68e176a48043aa0fada331eb7228630e829c4dcf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gatekeeper@sha256:4fdcf1bc517fdf1e2f12fcdc444a89b4219edfcf478868e309036b82469a2b91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:58daac95f7a87979ca4484f2077c0dd63cf76e103291ea4b87a0d53c1d621ea3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gatekeeper@sha256:9aa51a3a80ae9c0ea5f639818d796c5d380f2f83791b8cf39bc16e84a2ceeb26
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:d56b6e08c560b4bf667e902678cc446bda6802d7b25bea589915840ad72546bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:b6b810c7911527243c50de49a2ad98bc1c99f4a4bbed33bc8b39c8be864753e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:55657e5b6e103480b71aa38ed24f5fe2fe5c18ac52278b54298f436a7f0aa667
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:8ad0c4f384b90dbb4cd62fab966cee70468bbfb730bac5c17c2a18accec02cac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:6a9ba9e05dea141bccec615c8b466917b4d8f287111f4174a907132042b277f7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:8b8b84de957aa12dad65c800aaa3e1656ea2b02c1ca4d4bba247a5bf0f85d9fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:996d388385f68f30e705d8bbb96676d6e17a5126248671f2cf225314036682b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:9b557ed86c8452ff514a4f05d7dac51ed82142d0e9d6a82cd1ea405cfe69a901
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:2770f6a631a2d8d39532a2ed3f579f8314ac57e05f23c5ce0f76f9e85837836a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:a48e95d9a7513a0b06067e09f70c6059ffe179a48b286e0d5c39268962de5b72
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:660823be2ae01df83eeee04473c0f6a23d4e1bc3aef06136d57ac4efc7ebfc22
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:e3e478fb7b823f1b1abf0d6d8beab7263391f15479fdbd740d11675ca89a5781