Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.23.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.23, 3.23-debian, 3.23-debian13, 3.23.1, 3.23.1-debian, 3.23.1-debian13

Index digest:

sha256:696a12d373eaae9f06697f3c3eff2351b0fee8677b6214cc5e59e08bd0a0c75c

Manifest digest:

sha256:bf6be2cb81573356f700f37774ef3d7461c8d231cb21e616928e5e8cfe557ed1

Size

21.26 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:4f718137597bab7a55e8bdd55e15e36e61a3e133fe9c8dada690f682929290a0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:3009a1b3ac80c56965a68facd4621f53e6ef18bc13ffbbff0feefc91f9ee1348
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:931167686cdf2c1a70e7522130d7bfc9c51711243e4e50485b6802c0b04ca551
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:99ad190563753df848a51159b4e71342dfca552c09b965a556866bdc92f22bb0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:c0d6d6497d9c9f2fc9bb07623a8c30b959564cf6cc5e33cee698ebc405e33ffa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:768b4dbb7cfd143ddb121a24e61ce3c34bde08229290ac6cb0d7cc6787b933db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:1e200f78f5e8586362f41c4fca907f6dfbb8bb9fa7c7772267b3db206d40583f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:bb14ac96836a80787e3c90fbe84ada608fec9bf0acfb1c5f5b8bed2bafb2d0c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:3366fc24c850ed5ff9f7eb2de5192995f1360234b52dd81889c69f0cc633d4f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:33d6c732efdf96487788e3d9b33b8243ada1137173742c2685cac92a05384392
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:b34af9102e6c78d4e715c0ad3142a89cfe61adac0f470a26b5786a60cbc008fc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:2e8a57db18a1d33d656657e9be74dfdf67907d7a0bd59c05ed825f761b27ccf4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:8b827b6ae12105a5fe0d6dffa48a5191953b7de122aa6d4757f38d222409d083
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:f056e7cc69b08f869b304f01bb4da5bc2d90730af4937f1000e336c3193a5c32
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:a556778f5bb82a88e722b6fd123aa7216e9d6a10d82d47c8b86f8af55c224f1d