Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.22-debian-dev, 3.22-debian13-dev, 3.22-dev, 3.22.2-debian-dev, 3.22.2-debian13-dev, 3.22.2-dev

Index digest:

sha256:463a53646501b25d35b64b37219fb62c65e9438812042569293c4cc91355808a

Manifest digest:

sha256:140f30f1236cbc93028c99dc09d279ca290fcca39005a93c93637c7bc40aacd2

Size

63.66 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:713349a67c3c9d514d97b5d9f29f3ab48be9426fae80ca284d651712daf26779
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:a44f8ebe1f18fd36b8389b7116ede22f06e5aef08f641d6418b655baaf659975
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:3bf6543d47db47f89bd5891128ba3e5697546b972d3e9a7b021d38fb783d8db6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:aa6998c31232f671276e9a4caa61a4f368c93a547369f99331340e1318787889
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:a76d88c3302e87648a9c141cd2e9124d0f4c51075a9d79e889871ee023f2f5bf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:bc00092f3d0fd1327feebba37b24b051c87a443281de45f6adeadbc5bed5a9e7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:96e7a6d78e69bbbb02be9ce903289068ef1c7200df1f8d31e0f4b9f742fd1007
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:99d2918aff82877914ba126a4ce92097e97c3e745d9ae45bdd716513aa8dc721
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:60104ec8e6239058fc9ec46c7c1e77f03ff3ab2c06e1052810f3b2c09ca58ade
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:e2a137fb5d19f8db6ca6034c91d0e473a29fef601b290220f1e8778b202e4a01
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:c88bad35e1cdc8258c8b4d29f4db378dbd34ab0563880f027c0062af10352af7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:38fec07071441261f8dc4a4d245be995e6b803ca687d36427e8fd3270c28571d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:ce330b937b57975931f168743dad1015aaef3e4e4c64dd883969741be714540f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:ed78ffac5a4da1f2a58474010c00a2f233e399281322ff1b4e6f890caea3bdf6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:777d86356729666ca4d67539bd749223df7925d29df84503db42d1d0d696680e