Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.12-alpine-fips-dev, 2.12-alpine3.24-fips-dev, 2.12.9-alpine-fips-dev, 2.12.9-alpine3.24-fips-dev

Index digest:

sha256:03d5effc16c31fec8a93c0aba94c850c8e3bd7e85ffec33eba960671ee822514

Manifest digest:

sha256:df6c79ec8df78bb239bb8e811cba3c96886c00b1aec4da828b7d85fd681f9b08

Size

49.11 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:383de3f0a21bc297fd3fbe459b1c885555cb20a1c3fc29da30aca39441287eb7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:146b5964bb3c8642bb23dfee7d1bb2956afd8b0cf9619cf1b605704584b44940
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/forklift-api@sha256:3141b4ea1be23bbaef98cb9a5998aa462c1ac4f58d9ef806d038dd9fb0e20134
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:2af2220706fa4ed5c89e4604130bf4df841704607b0e476141cae5c3c7492a1f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/forklift-api@sha256:90750e027b9dda78afad8c7bcb2808cdc0c2e26753b8646b015259e3537329e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:358af14c5cd63801750be5d123be6b4d97562175948ae66dd6c09f4c0b426831
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:a197270e954eb7cd6f0e966d19b49e9b2ec1218db53e12b27ea934b951090b76
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:80fa8cf7aace16a3fabf0f2e314942570b61620ef8dff00dbb46d0551baaa870
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:f98f31997bea98ad24276de353a40cf714e6c64a4b8ebe20cde5626a6e1658d9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:490e2aed3ed0ecae96b774abe162e65a777c3f535db6cc8d9a48419b93c48032
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:53b13a9e64a8b85111618cd0ffc125f5f14dd0ccb6baa8f89147f8d82f2eac5e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:8df9252b5126cbd767ca3db47f8b6178dde8db69a4d58a841d29da96d7001863
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:893220001c7550dd538d0fba1fc4c6e3148ae6a3533bed185be07107ab70aa65
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:4b2fa1f1fff88d79f07a9da53e0978ae1c9f5f126d31c7187185f59e390e1318
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:ac7a9bdd0019ec15baf50a4e5ad3d2244ce590b5aed9bb2b0dfae45ab3cfc919
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:5edc6a84b7579c2c53962bbac83e9aacee717266e66dc4e4e85f1b1e93865b17
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:e29e8a92047604bd2cbc322b4f99a86ecd3919239ac13553766422452f58db74