Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips, 29-alpine3.24-fips, 29.8-alpine-fips, 29.8-alpine3.24-fips, 29.8.2-alpine-fips, 29.8.2-alpine3.24-fips

Index digest:

sha256:418bb02977744080007abab5583ee7cf82e6e63dd2cbcbcb96e4b8001932a8ae

Manifest digest:

sha256:282ad3ff36eb1a71f1baf217886bf4ca4b0b55014ba98fea661f2c8c26ea50e0

Size

101.97 MB

Last pushed

2 hours ago

Vulnerabilities

1
1
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:b8c99485cb7678eccaeb7d370942d8d07af63be3cee1dc1ff06d9552b701e826
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:6106ad9f5a59fcf3dd57b91e0273e5223f029d0a57e3c0e173746dac8185aff6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:35f01b2714ab24adf504f52e31319f0e6f71935618856180f86e73706bb6b13a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:6e5f783f20ba3e0938f538b6d4aa89cc818129839acf7edb8a7f9f2564d27084
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:b28c55d519e67131332639f86807bb73e2d9776aeb518310af9cc22cb42c06ff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:3d39776e6fce5b8402d7e529400d2df3d1c99c47ebf2161a7232b834207a0cda
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:eeccbd28ad22f19967e387ad4c37df006066094a4c0ed88e89be60b3b70330d0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:107ce8ffc4ffbc09616e54613fbe1467888b87d5e6c3cdb7c7c1cb770246bbd8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:096074ab484a6beed50c9e37a90e2b8994401f910220d851f3cf9e4cc77205f6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:6f28a8e9a86743eff1eea9202d5103d855b0822fbdfbb737842f1813d35f7ee3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:6fce56f70f383bd909770667146cd4df71a2b9f772bd64fe16c7b437e799741f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:63eb00ce1181b90ba0d5d8ff0dc27b8d72ac22814fe2b4a41ffd35dade550708
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:98bf90b73c1492d6df686a20132be0ef1706c01c66767c445cc240335ad6418d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:92a44189be28149284a1b92625bc75f42af9077f63fa1839eebfbad7c65fdad9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:47030adf6118d8a9d5108463b01f0486389fe0a9dca6268b6e867ceb3691141c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:cf2dcdc77ac08cebc919e1b5a11f709ecdb9c88a3a4b45434af8583b53f1422e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:bc5a6f7a56c09ddaec75d9e1e0f8357c796ef3eaacef4cf1c3ec4fe1aa56601f