Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.12-alpine, 2.12-alpine3.24, 2.12.10-alpine, 2.12.10-alpine3.24

Index digest:

sha256:c2a65ddc5aa26b0858128d7f548226e22aca6bedd5ab7fd8600101c1e7ece30d

Manifest digest:

sha256:d89b5e4db42bf68b789581332a7f4d0fbc9a750c2c422cbcad04fa77562b6f37

Size

21.72 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:d33796a4e89599bd7196ebef93d914c5e3bb2ba8ece53a9dff3dabca6d2a1954
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:c9c484a81306d315c50d8e7d53d58f1503f7c0d36f92de4b169803b3e4824212
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:006ea069fbecece3fbdebf260701a8a2c47a21a4bac2f8fb818a9a238ada87d7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:2c9955136c7ecfd256d9f4471e91a3ec0785affb12a21c11753d55a098d8576f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:3d610ad45b224abb8748bbb905658e4a52b3046ba722f01bfb0e419494d69196
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:bf0d9d68c929825e8f5b0d16fa0a8b86b74fb1f9292b0672cc797d05eaaa2c7c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:3be78648ce17d75b280bbaa27950bb88ad09873c5853be8b715396e2b54b169b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:a8ca79455c891dc083ba46532c8641467812e78f98eec2810e05e87617de0abd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:e5b6ddf2028fd7cf350f4e8d25006579da844a101b607dfc6c13573980c529bc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:94eb55ade4e6a483e6e57c38ee4fa439896dddf72d83eb17d89d4a93d03f2eec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:2eee78d6986156d94cdf48841193e31d67b7d46d63d7fee98db9f3e9238a8d95
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:8f0f3f0bf3953b1e14191850263d1c4179a3b4efd86f5da24d7997033deb2d18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:3725accced4449217c727531cdefe7e7602fd2f11e3fef91aeaad5c7d4117409
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:69ecc37bc6aba7929253af27d0f87cfbac2222568c3f3ceb88d8df57f5e1dcae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:7659c0296051abf7f015f08744bae104334d7232df26f1b4e46dcbb00e7a9420