Sign inSign up
Forklift Must-Gather

dhi.io/forklift-must-gather

Forklift Must-Gather 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.10, 2.12.10-debian, 2.12.10-debian13

Index digest:

sha256:600bffd661b92536aae600920462ec8cbbf557b235cfaf9d27ad124bbd32e4c4

Manifest digest:

sha256:b33c2e49c751a274fb72d49f9d26ab3d9235cf387959fdd7395268addff2d3ba

Size

38.72 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-must-gather:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-must-gather:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-must-gather@sha256:fb8919c2f0374e45efc933774c34b822af7e085fa52a8e0ca9fdc16b178aad9a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-must-gather@sha256:976b0a841cb526451675c727655ab493528c94fb5b050a8bfe8142b0f23e58fd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-must-gather@sha256:a0065245121760d3be788ed66a5692fd7a39e9fb11d9035472ad7da543a82c13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-must-gather@sha256:c3c72760e8f5a3db8e8180fca518ed8bee3e4e599170df1b3ab13aa8da866e16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-must-gather@sha256:680320e713ced0d5c5de70a2991b7569a7726883e99534092f01adce3c9c581e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-must-gather@sha256:ce3384f236c6db3c5cbb19ac92ecf608b6ffc2e57b34b045d401708f312b94c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-must-gather@sha256:09a5b27c48d98e4cdbc5e68043afe508db89eff77037da5f030e138b3c4aa616
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-must-gather@sha256:1ff5517e5030aa92ecaf23b281b92ca19c12e040d5b5e8b6eeae1467c50abeb7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-must-gather@sha256:ed03da0fa70a235a7999a4b7ac999b69b02dbe3ad0ec67a04f849d0bb2353d2e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-must-gather@sha256:4fabcf53b02e42e957a74b9ecd0c47b6eda77b07933eeb88b377baca09943637
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-must-gather@sha256:2f177609ad12b87db60c4a170d6c8d63faee658613caadd725d0aa05e7221a33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-must-gather@sha256:980ab3d1ef8f42aac57b5069a5159b6f9de90fd8cc8994ae07fa1ec2ad7470b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-must-gather@sha256:0671b2172540655fa1804619bbd45c7e48583e76fbe56191dc59aa6b7d9e35d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-must-gather@sha256:3f09a4327615fda786b0f1830a993e08cebf8066795f6e2ea218deda21bdc6a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-must-gather@sha256:08cf022ad60db9036efd768bebaa9f09c2a6f6c0dbe781d32cab11de2f0c17c3