Sign inSign up
Git MCP Server

dhi.io/git-mcp

Git MCP Server 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest

Index digest:

sha256:830ad2ff73e42ca1cd2092121226c37d92ed09290b15fd8f5176a4b57d6782c6

Manifest digest:

sha256:40ecfdcbcd5fc5f389db7fa995b1b6672efc909e9d25ab6d4e402ea47c7267e1

Size

48.10 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-mcp:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-mcp@sha256:e49c38e489366d866dcca4a50b8cde0efe8bddd651f0445bec5bd2465d4a4884
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-mcp@sha256:99da3f29bda051eb9fc38eb1ef03f65167995b95287127e1d2ec1eda7b0e1b0c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-mcp@sha256:262d33cc7ca9d54643b9a82d90db9f2bae5cff441d36b66edd163af78c99b6b8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-mcp@sha256:5d897b0308908e6123d3161f5120c45209336353580667ea32c1d6827dac3705
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-mcp@sha256:def060be5ca61d8c1f9754390df1c594437317490f6705e3b54515785cbe9081
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-mcp@sha256:f4db63a2a7256ae7b5a0d2f540f459a41537532ebfaeed4e0e51542860d60c7e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-mcp@sha256:536b6a58e11147bf6416cdf72cc61f73099f8e845d93b6196a95c82886accc4e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-mcp@sha256:f44fc42e405ae0cebb876930f4f448685922828227eb417e1bc87dd08995a278
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-mcp@sha256:713581d455129578c0fd7d4fb988c1af94d58cdede9aa23e1dc47c938251864c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-mcp@sha256:916620d38cf4761e39feca04a836a6dc42e3c3e45a45484a5b8f9c28f291e706
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-mcp@sha256:a59bd0f9849fb449f569af02d61e514028a1075e5202e9ff8f52527aee3b47c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-mcp@sha256:e6ac0d008f3bcafab5b3c51d0486fda60012fc8bf05dc68ac71994beccbcabbb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-mcp@sha256:8a513a0296f8bd4df870cb00aac86dcb43bc5b6528d5e2eb21e5a332535956af
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-mcp@sha256:f96419a68d472363124ac72f9f69abbcd7b914fa7f8856e981535be17a88542f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-mcp@sha256:6a05db81d37560719e889fdb7eedef686280c604afe44c47ec4db09c3f86c75a