Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips-dev, 2.56-alpine3.23-fips-dev, 2.56.0-alpine3.23-fips-dev

Index digest:

sha256:21c3779e2f948aa5e53868a3b00e421bbec4229c8105e661eaab2a380a74f389

Manifest digest:

sha256:50b73053e6c9cd387cedeaa69895c12d614d3e3f28778cf001a76c07f7446192

Size

16.02 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:8e5efa83301f92055a0e537f60457d868880a33995cfe8485bcd8b735b1d6718
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:bb51061dbee082f34741b41e7a9b2b9ab1229c18ee4e3f227a0edf0f22a9a32b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:da995fb38f3118c117d4ad90b022481c12c0c4ffca0184e8c46ba477ed44b6b8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:58c5c6fc867aa6a3fec905e9c7cdc7e97f193c5580de65ce5f59834a91590bb0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:e4f5d81bbe0378f767336a8f4a924a4167173a6dc6a7dd78f9226a2ed0a4dda8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:71c083cc58abd7958b004a57df0dec2732bc975967372f4fd560d9c78ce93347
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:f82552b437bda1bc457ed6aef425eb05abb1b04276a2f3c3bbc2e670d79ab732
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:2411fa1ef50395c10285543d668490695ed7e85ec293058fe5bc7544d87d88b7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:8f8429ecc69aa59cdae0335134f5333c9bdeabbbf994511a8f51c7a66c297494
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:194f3e4998aa6904ea5a060389a3e06287f99fee2e8846f1bf43ad36ee0a7ebd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:d345f862164caf8ec6502738e87557599eed01b33b1d770bd702c29a42d4e9b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:cb9b70017b3ff00b70463f13426fbe3f3bc5a52386f338ff746ae6456776b41a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:eed7441abc75e03e98850814ac847a4d8cb2986e1ba83b6f4e19f0f8a539dee7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:54abfcb02e6e03806a5d743be7fc78adf185600fd54052952e81e1f2e5133d1f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:d55097d508eeb44c835192387f9210822754ac866f9e02ea78976ed5faf8e024
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:1159b6a1fa12a2d6270227f48390f0cef168bff84c6c63db0c1b577a52669686
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:542b5c613372202bacc09f8d89de3a37313d3932a4c911544e5e40597bc813ed