Sign inSign up
Gatekeeper

dhi.io/gatekeeper

Gatekeeper 3.22.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.22-debian-dev, 3.22-debian13-dev, 3.22-dev, 3.22.2-debian-dev, 3.22.2-debian13-dev, 3.22.2-dev

Index digest:

sha256:9bcd4ace2b1f85e2ae5b39a86c77266a286616aa7c3e998da618696a01403b61

Manifest digest:

sha256:8b58a06a6b390b54eef04aa11eecb6a80ab7196adf353d79178bb493947d7079

Size

63.73 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gatekeeper:3.22-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gatekeeper:3.22-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gatekeeper@sha256:0edb8179c1f9dc4941535e968813950ca6ac015ee80c6de66e7d43449784a998
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gatekeeper@sha256:c7a9ebb570d5e545af7ee5bd5d59a2c6c3d4305e8143d59a09d16fac6b67c9c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gatekeeper@sha256:c4ac1a873995f7aceab6ea8b4fd8d850869660f88455178de209c34de0cc7827
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gatekeeper@sha256:57bfdb6295da4b95fa78e3246b0137de527a10b7ea9e6a94d3815199b1eb0dba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gatekeeper@sha256:c197d55061f7bf30bb5c5f99b3bb7d9d85eb68825c05622c7e7fdfc08d5838fa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gatekeeper@sha256:059bb3dba8a0d91ef8f8d17487e8084916c548862ca4f06f5fd587ccbd44038b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gatekeeper@sha256:2591475e44c23b592eacb65ee89d351700831bb3581880a9f09cd2d21d5071b2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gatekeeper@sha256:491031b75ab9537dc2ffd00c50e18604bf8c5628a5ba4feb9e6f3f032b74f9f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gatekeeper@sha256:adcde5e4fd9bbfa4ea5c54ca28dd770bcb78f7cd62217099cfe73625f4a6e19f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gatekeeper@sha256:5908bf60f4c8235a869484d5edc5cbd032af155d11ad848aa3ca72325fbb0fad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gatekeeper@sha256:df68c0d6225f1685b869023d83ce4da34eefdfe3b286192d3da469b4eda37772
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gatekeeper@sha256:4d4c4bfe461e832a13ff9bab7714d202ef8fd93743bc05a0595cda9d8c4cbef4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gatekeeper@sha256:b2292eae8ac7f76d0c2273015142cefa7145061e62689e63d3cc7b3b3261dd55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gatekeeper@sha256:f1c007ffc074c0f985238566992a80ea482cab208e9724ee82136b1f4a15880f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gatekeeper@sha256:ef593d016f628300e728c42e584541070f2f3245a22b7401ceac76cd54be8832