Sign inSign up
Fetch MCP Server

dhi.io/fetch-mcp

Fetch MCP Server 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest

Index digest:

sha256:1e93d2b951f05c1e75cd80cf6beeebd63460bc531a29f89c662f02f25daa3466

Manifest digest:

sha256:d0cfce7586e8f5a9223e138d6642ed49e8336a4c4765f206d21ad2d9ffda89e5

Size

31.11 MB

Last pushed

12 hours ago

Vulnerabilities

0
2
4
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fetch-mcp:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fetch-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fetch-mcp@sha256:233f4ce900389e6c6e8668363983f502a41515d4ceb189ae48293a934287a437
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fetch-mcp@sha256:9779e3fa460356b3d00992c31867009c0207908e3a73ee8c9ab662534b4251eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fetch-mcp@sha256:03d2435a0970a00013b08236aa1e089b0dd25db8b644fb9456a7599e49e02e11
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fetch-mcp@sha256:0778eaf2618183435e572f98c8c068def8747f73da8fc023ef30cffccfc3cbe1
MCP server.json v1https://modelcontextprotocol.io/server.json/v1dhi.io/fetch-mcp@sha256:50486d31bd132a7385960534bc879282786606d6a27aa8ad56adbb386326ad1b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fetch-mcp@sha256:988e74232360140c28964f91196b86cab0a58aa0d66829a6b24b323431a44301
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fetch-mcp@sha256:52f1f51ce1ca61f29cd82b0a4a24980ca75de0e8ea0d3db3e52e60e0187d46b0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fetch-mcp@sha256:280771359c102fbccd3f037b2a03658111e26fa3a4132f0553fbef3facb6ba5f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fetch-mcp@sha256:ba6983845fb9b4fc963ff8058bf6431c8ac100f9b7993db55fc7b0d69e131160
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fetch-mcp@sha256:fbf34bd39a637e9ed2e0381e1de89e87f0b8b55363629bba4949de01cd542c09
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fetch-mcp@sha256:a12011d68a47cc36f22764653cf0531c08e59e50d95a29a5aab8af208c372506
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fetch-mcp@sha256:81bc315cb8d7d70ed8cd653e8307c0ee6eb071d6e2f7a4ec5040483f4cffb993
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fetch-mcp@sha256:6276144d7ee1a688818304b093ce45923ea59db93fefc5d4e15f292de75b7943
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fetch-mcp@sha256:62745afffad5c714ed6dfadecd6c69e50c6cd539d2da5988900adde216c462bf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fetch-mcp@sha256:368ad2c386611006d7238957f54f8f962e022c76130e21af5f01c9bbd443c832
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fetch-mcp@sha256:88f11ec6548cb15baac63366d53dbff907d33353ceb5ef791567319ba9fffc70