dhi.io/git-mcp
2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest
sha256:037af6fd57e82f0cdaa72b2a3e9290fe7b93c274076e5170266bf67646a6904f
Manifest digest:sha256:1f5975c3b18e92067464e308bee4b508ce133c73eebbbb5f155790638fe64efa
Size
48.07 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/git-mcp:20262. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/git-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/git-mcp@sha256:e104fdfcab741384a531aaef1b3939b9fdb317294d427bcd2246b22fee5edbde |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/git-mcp@sha256:35fde404e089a6e929dfefe0e27614f15fa09c8bc4a17ef1023b6c0ba4919695 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/git-mcp@sha256:95ce79bbf0363db43aa7c8eaf77e8efe3e8cb3231f76fd474a0bf07ae7eb68df |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/git-mcp@sha256:30e97871bc1b0e699ef863e363c3284233673d55ff389aed59b6810fba053fa4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/git-mcp@sha256:74a56edad0ac7f74a09d5257e44641afbc8b4d02d0cebf54e0e199d911569f72 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/git-mcp@sha256:06cbe30ef6795f31052273eaa37f8f3f4035183b8ef2c07c9ead67f4d3d5b4cb |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/git-mcp@sha256:8f96cc187e7c83f338d2be97f9c2e2dd95e5dbb9ba560cf09ef4bf2ed9cf9af6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/git-mcp@sha256:93e20a8e0c1d5dc7531f6c5babdd2264df09f1cc580bbe7beb4e0ed25aae6ae8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/git-mcp@sha256:01e4d0fbe55e57f2bdc164052c7b1412830d33d52b16668402c6ed9457d3752c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/git-mcp@sha256:bfb2bec694350c8af5a9f2d73b475f272ca7a56ca906c3ceb465068c1ed4b2a3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/git-mcp@sha256:ab6e8c5dd8e5acbd1d520caa07bf975d2665c42189999d65727a85f738bba833 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/git-mcp@sha256:443fc2c332127eea95fb93b685bd519b9fcc357597c3050ac438f2acc7f353d9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/git-mcp@sha256:13aff0f32636dc13381474b299961a265c6182843c3a5cf74f3b48b6fa9e6db3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/git-mcp@sha256:d6d4d02eb9c457931c2479c9e80f20b4c44fe17cea4607fbba4d46da1abb9072 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/git-mcp@sha256:d6d165eeeb8f7f4a6c4f05520d7e6d36dd9f4ec43d338dea5956f2ef181a751f |