Sign inSign up
Git MCP Server

dhi.io/git-mcp

Git MCP Server 2026.x

CIS
linux/arm64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest

Index digest:

sha256:b9e860876c176384029af3e7c55569fc0de8ed8f9abedbcb56c8083fb052357b

Manifest digest:

sha256:3a8733b0e736cff63f93e2e8f704e423f83f04b3701f20b4bfbbfb949ac17663

Size

48.52 MB

Last pushed

11 hours ago

Vulnerabilities

0
1
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-mcp:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-mcp@sha256:4c3c6e8f68f775d063afc935ce9766d9697b735c11bd187b1d69a26983f4a99c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-mcp@sha256:bc15cebe52e42d83bacb3a055c00399551a0e550d27c434550ff1aea6a4f5590
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-mcp@sha256:c135c11b0ed8156ccd7977b040b8588baf1b087b9799cba48c6baf2701c37d6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-mcp@sha256:5eb61454f926ed68b61e61d08699655c4e04a2bb0bc288dae5ed4744c28039c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-mcp@sha256:7d2b82c7fc9de45fdcced6446703c9c49444c22233a642dcaa48d1d3183c4dd9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-mcp@sha256:40f38ccc1e565dab88af0644282e31d07b7a612183291304a6b953c7bdb641f6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-mcp@sha256:2a8a878cf014a85e43c24d879fc4f04f5edfb1c7c87568106db423146b7a4ac7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-mcp@sha256:14e8eeb5d19c8d6a94b15f100e115444c0de60ab0985ae6a6ac8afe51dfc4579
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-mcp@sha256:8d1774d9bcda89ae1efb3e9bbfd73d289e974771793168e8bfb78920cf9fc85d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-mcp@sha256:a68ea221c9a2dee84667b0aad4689124467dde016b23fd96b5be254797dfcd4d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-mcp@sha256:744a5d9ad637d9c7354ffb25817629badfc5a9f5edb5306c181a17482a6a8094
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-mcp@sha256:b34bbbc74e1b47c020f8cc5061b3f09f884af31cd98e4cbd70afdec543d1463b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-mcp@sha256:54d32f5a11a520f4140413b5cf0ede691bca512ee4246100997fd8a7f13d66df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-mcp@sha256:00b418ff65d78b0244a56b6912cd22c66f6783558cdbfc24204cce8da2925cde
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-mcp@sha256:ecf09d7f94b0a87018435ed9a80f3d7a3350ad06ee71aa037c83050886bcf60b