Sign inSign up
Git

dhi.io/git

Git 2.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-dev, 2.56-alpine3.23-dev, 2.56.0-alpine3.23-dev

Index digest:

sha256:1dc39effdd688d53339ec25af95562f8209d14a56157cca1f9bc7e03813605ee

Manifest digest:

sha256:fb5a6fbea08da9c82ae8d9642dce1eaf9f4998fe8b388a596ae3e20c314dce6b

Size

14.88 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:3078632e6f3db88d62466ba8a79f789f5b9141d2f87f094dbbca8a7f94d78f0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:be699ae8cc006785b198c6ad24b82f73d712a7aa73f11982123804314cdf0370
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:464d24201cbcbd418d15c5c7e46482aa099988aa5064388061abf23b9f22344d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:f3be5faede6b5aab1f0d0c0a7e9159d581ccfb60e123d3956235b939ea58d247
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:efeddcfa5bc5ec01261fc54e4f57401c37db156192b09658397781624384e19d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:395daec0b25c3f1e0742232a474bcd56d5e118e7820054d709d37497d01d7dba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:c174669426f704cdc82b94a9259a20027e2fe620eda0627359522d26e3d0f23c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:70a9b5987cb469eb1428ba1f38c6d0ba764e5b61153f68eea88994cc73c0a75e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:8addfda3db6bfdaa58ef34b16cf15734d29dae14d5b9413b7c8b2c6f0f107957
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:747a5673d16ef117d62dbc0ba5f27a19b499879ef4734a3a9f712ecd9d64ca69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:a75719692623f265c1d35ffa78ef33f3b7daec846cb9eecedf9628d5715533b4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:1d5f403f116ecbdfc8d1c8aee4798ad3aaa7219763b9c1c1a01c3a9c2f54d42c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:7da7b96a8e9daff7ed70e5212e573bfa107b302a34990721b44e6d2739f15088
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:f5fc12bf7ab0b1ae82fa80d0bad722ac1f27292be3687177e7ff085f56cb954c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:3b065abe16ce82ba5f49a134c8c23457aa949e9952deb7efeb60fc8922089a72