Sign inSign up
Git

dhi.io/git

Git 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-dev, 2.56-alpine3.23-dev, 2.56.0-alpine3.23-dev

Index digest:

sha256:affb4037d62a77b280935de6816aa539d96db5dcbb962ef73e29eec6ba96230b

Manifest digest:

sha256:ace995cc096b70bfb33b6a7d659740be9abfd0cb328f5878831e1f8f148f4ddb

Size

14.88 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:18079e83d053d97baab0b7c2059e2398a6a54939034f3923c5271da0ee039a9e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:8c6ba994d07195ddabbfeeb2fa48486b7b92902e390adbda11a9a76ad4d98aa8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:8be207d54851956b1bbaf7eff69f80643ca8c5f1ac4d203eb1363e681fae1456
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:22f93a8164652280c1d41bae249c04f606715ba6e39a261e51e2d09ff764a928
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:972b926d3d7a8c73b24a3970f0d82d4ebe3702f60b389f6e7ea5463d468fdf7f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:7b9526102b073fea6377053b355bbf893a275b46567ad12e793bd6d9ff983a25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:ca334ceee863facc6ab1fd57e3bb26b1a73acf7913d59968b222ccac1e9b4049
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:35fb81440fcf5fa2272cdd788259b817195e80b968a89c72d3365fa8d09bac13
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:b87af006882b6a03b3feb129a2b017051a53cf1eb96e3c178fbf02e0004ff542
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:88317b06fabde1ff21a65a543c21e77a9b19a04c4a67967ef2926c069a21bbcf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:2cbedf5e669f3f98fec9027ef69697b3a49bf4cb59b1b8c0b6e45a3ac1caa7a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:11802c5872492e3c68a61fb975dfda57b47eb4565995e49bb373e2e4e9e92fda
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:7680d5bc06806c48510bb9f33b24c3873727acfc38a9b428808077eb0ba3cdaa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:d13cdbc0534a38b0f6e973ada5e0c6157785e4f7f01b7cdb4920d6272e0f22e9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:c372d9b16341dcf7c9ac6fabc6b955e08de67896ba6eeaf2da4fdee44e95ceb2