Sign inSign up
Forklift Validation

dhi.io/forklift-validation

Forklift Validation 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.9, 2.12.9-debian, 2.12.9-debian13

Index digest:

sha256:99e2e97d149e313e54c2d54ee7815c96c182854cb212072aa39e15c07b9c859b

Manifest digest:

sha256:d552a455d9dceb098eb31d4e46b1842ea78daef73555f6dd6d9e11b47a4f5759

Size

16.49 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-validation:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-validation:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-validation@sha256:e581c89c10bc3159f3db9ea9faa2ce914be9590d072fa738d18ea8748030c34d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-validation@sha256:b9b5d5540f74e07d2b14ac4defedd4f1056472e91c2fa151012d1a7854e4d9a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-validation@sha256:77880a823ae6b0b07bee24ada89ddfbf9d57265e7d89aea61433c0e1393436cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-validation@sha256:5af39d3c488fdd94650bb81c7e06831cc88bf7d0cc438012105c8693cb262feb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-validation@sha256:a5114f45e2c112d7e66497fe3848d4dab97a3055602e4dd3016bc88df381f1a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-validation@sha256:ed7e7403b41b135fe3250a6b809fd99fdeb77b281268169c0b54291f668e4c61
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-validation@sha256:cf67856e7d6212f28bb4233ba1370d0cb3e5799af4f8d4c84090080f36bf5cc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-validation@sha256:116dd8a3a92abf37b6d8715bd17285b9fe4e101ddd95cc6f6494228268afe2f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-validation@sha256:d966128f739d0f0a37ed9bbdc6f8e83b72d1e64aa2bf1d14f8a738be108f0628
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-validation@sha256:8735ad5134ca06b984271da409f6ae44917b9fa8bd48da57b1bebf41623dd0b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-validation@sha256:11a2cc39bf769cc36696ef0d8a2ac8a7fa27ea6989675362c7beac02556bafc8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-validation@sha256:e09683127c45abc4bdb2fb89c2d5d31e25409c9e547e73174829ed669cf499a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-validation@sha256:9a219dde35065bd8e17bf39077c9c243f080750fb1fd3670d8bd054a9dbd64dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-validation@sha256:7950102c58cf2ca9d7e69b151f42c28dda81cb476f78a4f5d53236b7541bbc2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-validation@sha256:8884171a288b2c428d03388cc88b67762d230032e5214da02e4e3c2429e6f6aa