Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

29-alpine-dev, 29-alpine3.24-dev, 29.8-alpine-dev, 29.8-alpine3.24-dev, 29.8.2-alpine-dev, 29.8.2-alpine3.24-dev

Index digest:

sha256:76887362cc5471d7a29a3a409271327d6db01ff25ba640ebf407f1210e762cbe

Manifest digest:

sha256:ee07dc253b8b54e0b299bb796a200fa18bdb3971c45f47c23628d0256a61aa7d

Size

102.63 MB

Last pushed

16 hours ago

Vulnerabilities

1
1
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:06e453ea5448a6137bddb720d044fa0d0849c2706bd11a13b19da22802ae2c4e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:864634f50678720c8bf6e96d969e9240e1bc16394c7745e558fd2855b59c031f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:b9f6d9cee64715a66f9d60f6ed8af04b848e5e5e1b661f7b85454ad42d5380de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:6b895fc2f6e2df9513dceb52d9912feb7cc640309b82c20045e906e7582bba0b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:596cde8c820708767e20f1ea34dbd26a7d0b5bb9cbe842b036beca83072b0f3d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:b2f8a3add4f73ee771d6158dc59be3d4194eb2606a4973b15ee0278b62afa396
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:92205f6cd1758408e844e8eb5cc1450169ef43262803a9fadf01e927ec64398e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:78451893ea8fd07f24d4de059bdb4e9fa688963b2974cea9b5343e8a7f335d65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:d24c3c545e16d2ef9583629ff4638fce6061262b8d7c3ae8cb4aac87b410b3ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:a547eb1a1de75c9bbbae9c362d97a996f1d0bbb105b45d0bb4df93902272f2ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:41fd1b8be54aea9d151fea55f4c9ab378908149757ca65980987b83f27c7bb12
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:66164458106d81c26928407c4c87314424f9a6e87211e3f66a808ddcad30550c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:1080823cc5278caa814a09f23b303d4bd5478141387580f201f320308dd424e7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:d901eca157676e9cda9bcc29237cb541bfdf29e29a198f4f64ed30128cc499aa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:00b0ab8b77045e873ec09cd0593fadcd53b083ccde50fbd06beea40aa89a8d14