Sign inSign up
Git

dhi.io/git

Git 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-dev, 2.56-alpine3.23-dev, 2.56.0-alpine3.23-dev

Index digest:

sha256:89ae567b145648cb4d75cf908284086eaecfdaa5022d6d78053c8d74605696c8

Manifest digest:

sha256:12bb5ad63b749eae52278a0888b06218d8ee06bb4502f3f051fcc0d2b22908a8

Size

14.87 MB

Last pushed

1 day ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:6f256f7dcc92767f3230dd9b907454c3157e14da29a574b74b7eef6556422b90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:460ab8ede485cd12dbc53805622457ccff2cd251e4e011abeda37ac652ed3a75
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:4272577f37db91fdff684f66da134634de30a086d9193fb33fc6a68534369f22
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:1cbe816e5cffc3c9fcfcd750279c93ce52a63a37160f7140f8928c5f6d5ce42f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:cfbae2e7182289600f9ab77b7a09934dfb3ce13bedfe5efb801f249e1432dd37
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:7e00183d6b548540e94fea3bf6efb998a4404138ba04722b8db17542c8528cbd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:380dd02395c121ac1876c2fffafd31abccdfc6072153381135be5062ca2d4263
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:cbc5096ed92c1b7d564b9055d471e84a9285a4af7bca2f271c8a34db40d587f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:a0b1d8dc684c0fa6e4f0537e7012b17f20e8d57f5a1da90e072b9c447766b7a7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:e50e4214906b1950b9ecd5b36368304efad886bbfb4ac8383625a6e6b6e5a691
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:3b0c5cb990dc0ccf1ec362d42b9d08ed0f08c2a8f43769fd3577193f20e24d8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:de85cca7ef8bc0333e618749916f6a9cc0ff416c9e469e2bf75e943a3c38a4c3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:851d80960afe26b29ed47ea9b2742e05d12166de69039c7c591a72a7852d63b1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:37b52a227abea8e00a1fcf581cbf2ca50d354554d0f17cb3e1cb33c88e4aa78c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:afbdc530a5e5b7dfc238f9a8991f75df4cb333ad8201fbf5e8c04c71deb474d5