Sign inSign up
Git-sync

dhi.io/git-sync

git-sync 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.1-debian-fips, 4.7.1-debian13-fips, 4.7.1-fips

Index digest:

sha256:0afe0179430a181f591d19ed3970b3b8c06de344a6bc120a1c6050c5236fa298

Manifest digest:

sha256:81951a052812e1afd8d4bf3dd451e80d22a01a6e5c6567794cb7ee756ba2a05a

Size

43.45 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-sync:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-sync:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-sync@sha256:7d089fa272053567dae70e5fb9d4d7cb234cc123c2644b209487c655a2b2846c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-sync@sha256:56697d6d843dee30c5d252bdd50f380ef31c5637dc4473322665f771c4aceb28
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git-sync@sha256:21efde0d877f84b3c8aa96fd449f0e7c9346883766a0911712321b4089d50ea4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-sync@sha256:698d551500dd6a4cc54d4c6a01162d5c1fef841c480600cc80c24c528468ed36
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git-sync@sha256:3c509d0c497e38a88a7a3796094991a59d8020d2a1e087c6deffe183cef29a17
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-sync@sha256:b6ca82e4b58cc0893370d789e4da22ff06375778a333d5c65d2f4779eddc2528
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-sync@sha256:63875a1f1a8f71e39683bca9031f02d36854225147fb72fe68a9dbb7582b07f7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-sync@sha256:347f79c69a3ba4e8d818d6d4250c77e29c2748b6e1159185544038b02895a984
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-sync@sha256:bf41d40d44f010a191f03bab75c4c4d698a0062a34fb31ae6b25698f3cb0eb0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-sync@sha256:dcb3252af6d4c587bebda269d01aa1409f0eff7435da4ddd0fe63920a8741490
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-sync@sha256:bb13c8796fc717ada004ab1c486cfff8a7af02a56c1816516d93189e1df8078e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-sync@sha256:1c804c633cd805355e12c3d57e84d1cc792d097fbf302ddf6f4aa99b45d670a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-sync@sha256:933b774edf9baecbd217f15831465be52ed8b834b72af2e64bf6bace994e8314
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-sync@sha256:4e3448335ccabd21d7b8edda77a7072dfadc5bab6ad4de60935d0a0cab06e56a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-sync@sha256:b7829d0b0d3c2f84f5b356da4b2389a6be8b517e7153423ab92eac2e9b62c3db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-sync@sha256:e50acf9aa80422bcc66c3ca31ffe24d5fe7849c78c7c9ea4e763860596845d61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-sync@sha256:c142c5b3d886cda38a7dfe1f2e1c5a6bb95a60cd61e7f1f3388c8183dec5c28d