Sign inSign up
Git-sync

dhi.io/git-sync

git-sync 4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.1-debian-fips, 4.7.1-debian13-fips, 4.7.1-fips

Index digest:

sha256:c862410f84f66721ab0c65f4221704b16f57c9273051b4dfb9006ac86023d3e2

Manifest digest:

sha256:e87603543c64900bf70bd115054945cb475499f9af4376515c3d15697f2ac0f5

Size

43.45 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-sync:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-sync:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-sync@sha256:68f8642f95c8c62c8f39096130dd2dd07a5da62e44db39319ecbd7379161e344
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-sync@sha256:f7613f643d600c929b1290e6d1dbeff3b81f13c64643c57e0b78e6b93263f121
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git-sync@sha256:ef454a969c640b24daf75033c4ca0b59861557f456fa091184d77f1af4cfc605
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-sync@sha256:53ff1ee0863e52f616409cdddbb94d02f30f3318f7ddb450224b811a0782854b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git-sync@sha256:da7a0cf19ad3860a82b7c4d684fb6afe292a8bcaed451255cdc7b3c096de0eaf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-sync@sha256:f18ecdd2361d1a284c29fb46277e7f610b6a7b4a3f1ed636e823b2281987e8f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-sync@sha256:8e7226083b828aaf7a5b4d6f2c6105597a0ebb026842b83be548e213998daa87
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-sync@sha256:f5f10f7696cf072d779217794ce68b7c6b173ccede303dfceb2190f7bffdd29a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-sync@sha256:5491d9b3a7359b4b28f064ed4b6427b73502a5a62ff1dcdb80230eaf472b2027
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-sync@sha256:f9993df83aaf30e91d4b66dc70de73c32e2373fde5696840e59e31405eb7fd60
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-sync@sha256:97cda1ce8a3fe541b9ffe6a4cae17b8250099a81ee85506b1b0a3538d7fa145a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-sync@sha256:af238f9c7d66b4138cd58ec039b2b8fdfe361f664d306daf31628d6b879a23dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-sync@sha256:ab9d71602f12803957b71a5cf367ca9c7ce7a56a5d03a896deb427c3668ce40f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-sync@sha256:59252bf697e135065aa4da42674fc822f372fc46cfd62f2d75aabd8f2b663e14
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-sync@sha256:1ddd36bdc9085b87eb24e25ed95303168e1b9c2d61336c6bcb88bcb912f510db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-sync@sha256:50104a7399f695e6ce88ee4bbaedf6beb48302e19797bf17ea09bf020207ba35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-sync@sha256:02a0c9d7bd7f19b5aea35ad1d00c558ae6c4711bff6d6f43d2905efb170338b9