Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips, 29-alpine3.24-fips, 29.8-alpine-fips, 29.8-alpine3.24-fips, 29.8.2-alpine-fips, 29.8.2-alpine3.24-fips

Index digest:

sha256:c516d0807a6ff637b3dc882cbfeb202274e124429eac1af5cd1735aa4197f832

Manifest digest:

sha256:9fd57d857fffd9686f65a83ae1b120780fc21cea07ca50c79398afd1e93ae2af

Size

101.97 MB

Last pushed

11 hours ago

Vulnerabilities

1
1
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:ab21b8f81d14cb145ef27746b65a7b22c80b0e8e75aa95e4d0d2b3dc4f35d5f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:5ee5afb7696dedb8bc3338355ffc68a19a7bb361ca58808e70205cc53333dcee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:d9b78695a178fc29f1008c7d22d6cf5081f8a9bd93398b5d031d48b685aa903d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:bc8ce83819e9a244874cf36167dc4bb4770f87710cddcc305b597915774f874e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:0327ee528f02e25e8c66e9301374f7277288dec6a1e6044cf6de320c7ffbeb35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:8cc9319f59563989ab675ab95b08d30f3ea51342401749fa8860cef7ff6c11cb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:35e08a41f7a5fb69719833a092685020ef9274aa4a3de75c05311dcfa6677060
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:82608ed1e21f77da0029f405d167290ed1a989bdb7a5bff55d47da841b8fadb6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:bca1f3ac7043ca8bedede4031f4007bb5627eb26e315a7fe00e4126d56e07cc3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:6164bc4a55c29dfc8be496b14258030c8153b15e2977771aedefbaffd58f6fe5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:a4eb5731b636d25511410721e215aca06dbb84b0a4d3cabd2c8834e67b9ab40a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:c7255971a5c4b2efbceb8198629332228dcb244106bb9aee18543b001a7e2be6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:c2818cc005f3b69410070844f9f72de0134b25a569ac7ce2a04d016b1a79ee14
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:c15bc20203bb5660043775b4867e46da766ffd5fafd18ae59c6f3f9f1dd3f773
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:b8de28df29e956883fc0810a5cbf0fadca798a14d8d23151896bc6179f85559a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:afd17e29e7f262b5cbafac0e3c9b0256fb7e1c14609e5c87275889ab5008782f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:a7653ad7933a98898f5a091913021ae319912ee631820ff666117a78b58c6fe3