Sign inSign up
Git-sync

dhi.io/git-sync

git-sync 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.1-debian-fips, 4.7.1-debian13-fips, 4.7.1-fips

Index digest:

sha256:1887d19d2414186b7839f9cc0cf29821a316e639661a2d46ab2674fe3d47b20f

Manifest digest:

sha256:c529d6ba785e9095b2d3ddb94fed23ace98396523a26a4f96da9952f8ffcf11b

Size

43.43 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
2
19
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-sync:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-sync:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-sync@sha256:ad633d96de40f3436f5bdc1133562e117beb8ec611a36e408a4478b550e91bf8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-sync@sha256:be78c073766e4fe1cdb5496142eaa781caea060482d83bbc2922faa3e5e35d61
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git-sync@sha256:43be1ffffda17a2456d1cd05701167b0473c761723e94d0240b8af3a130e1adf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-sync@sha256:22854d487412442dd080899dc550bb4003379113ca50bdd51871c2d466905194
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git-sync@sha256:18c501eca28bbd2f3ad4aced64b4c6c939a998809c901e815d27e7d1b7e54504
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-sync@sha256:f643ffb734d97289e521f904fdee6759203f90f97021b5eed35e5757b918e429
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-sync@sha256:ec7cffcc27b66b3d45da06d63f965d170fe983261fd014fb4937df93ddda4ca8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-sync@sha256:c4e120ec8cf1f120f9c8c0693917a8a7135032ead718aab4c5163ad4a5fc3b22
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-sync@sha256:83a5ce5c7b654ed0a15fdefa56713df080b7a98648f1a41793889b334fe65454
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-sync@sha256:a2539f6f083318955b97b9308c50958293e556ed326cff57aab3dc74920e7a1a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-sync@sha256:9c41355470f0e5a65381a55c08583bee028ae032c426800d7be186d6b846c334
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-sync@sha256:ad848862bdc7ea3cfe43e0287ea7fa361451042e2e763e8fc7502ab967505ac3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-sync@sha256:2ec774ae74dfb4e5f2f06022a247e060b051da5a5638ec7ceb6bb4e3e9dad0f6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-sync@sha256:ea37e6bd23fc7a3035ade331b4237d7c2f95e949ad9ebb76d11cf9ef5fb3acff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-sync@sha256:416a8fa4f41c91b6f15b4c5a6508a280ce4b49cf457c1116990e7ad388bcc7db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-sync@sha256:b875c71bad85dced638f3f953ee6c2262c1bf5a483c0453ded002411555bbf7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-sync@sha256:a4ece2f83384d8ba7aba77f7145118515e1d422b90a13c37014096fa56644da9