Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x

CIS
linux/amd64
alpine 3.24
Tags:

29-alpine, 29-alpine3.24, 29.8-alpine, 29.8-alpine3.24, 29.8.2-alpine, 29.8.2-alpine3.24

Index digest:

sha256:486f9cba5c3a47201bdaec1bfb1f8130b911d1f1e6df975ad02e986c7ffded80

Manifest digest:

sha256:2af423186db011e19a72c55d8eb492808cd0c06e09d3c326225ddbac63f0c3a3

Size

101.16 MB

Last pushed

14 hours ago

Vulnerabilities

1
1
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:89ebf0ca71be4a1fd736a8c404a87c2c23887c1efd9ab523348236be8cfcafe7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:37fb0d4d8b0513d581a77db85b494ff89b58ec769cee6f7fa36d79447ce1eac4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:4eb115662055ba3370f9aa2c92ba4b9515c418a076634ca8f0c1a17ac7efaf58
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:0ea08a3c2e8a9676b235f9507aabc1098e9c278a8456f3a50d389d00602af914
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:949883f36d5e72faf5347927d43cec0cccd8163f005c228f6b7e3a081129cfa8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:d6cde36c2cab5af075336adddc672292592cb4ca2ac293aeaf6fa8263fce99ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:cf8943457682bf11b166c476538a0b92e4f1fb457a7c2f12d76ec982b84a1590
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:ca107284a656d9e119deeba57bdc04ad707de34acf1db8ef590490ca8e863dce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:d1139ce25d7a9e43639d47f904c44181cec57abb6427336f7e57e0bc5cb14c32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:06c0d478bfb79b5e32dc4057452b1daa69b016fb9e6bd8d88a73a74d45581db0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:ba74d9d6783da5563117ef575047a3b5850e5c7f86197a683cfb09598245c6e3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:9a6246f20f6afae6869e0d4a19ae36350b5043622363a29f74580ecdf1ccb4b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:675f8f3edbdfda60c3cf70ce81fe1e2d286ffc478b286a192899ef92a6f90a97
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:eec528e45f5375bc3f7f02f59a6e58308737a718b336b78e647b0693a9f6dcac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:19eeb61fb93185bd6cc0e1ce3c0a09c61a28bf6c42ad0a1b21f4d32ab7730bab