dhi.io/git
2-alpine3.23-fips-dev, 2.56-alpine3.23-fips-dev, 2.56.0-alpine3.23-fips-dev
sha256:21c3779e2f948aa5e53868a3b00e421bbec4229c8105e661eaab2a380a74f389
Manifest digest:sha256:50b73053e6c9cd387cedeaa69895c12d614d3e3f28778cf001a76c07f7446192
Size
16.02 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/git:2-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/git:2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/git@sha256:8e5efa83301f92055a0e537f60457d868880a33995cfe8485bcd8b735b1d6718 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/git@sha256:bb51061dbee082f34741b41e7a9b2b9ab1229c18ee4e3f227a0edf0f22a9a32b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/git@sha256:da995fb38f3118c117d4ad90b022481c12c0c4ffca0184e8c46ba477ed44b6b8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/git@sha256:58c5c6fc867aa6a3fec905e9c7cdc7e97f193c5580de65ce5f59834a91590bb0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/git@sha256:e4f5d81bbe0378f767336a8f4a924a4167173a6dc6a7dd78f9226a2ed0a4dda8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/git@sha256:71c083cc58abd7958b004a57df0dec2732bc975967372f4fd560d9c78ce93347 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/git@sha256:f82552b437bda1bc457ed6aef425eb05abb1b04276a2f3c3bbc2e670d79ab732 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/git@sha256:2411fa1ef50395c10285543d668490695ed7e85ec293058fe5bc7544d87d88b7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/git@sha256:8f8429ecc69aa59cdae0335134f5333c9bdeabbbf994511a8f51c7a66c297494 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/git@sha256:194f3e4998aa6904ea5a060389a3e06287f99fee2e8846f1bf43ad36ee0a7ebd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/git@sha256:d345f862164caf8ec6502738e87557599eed01b33b1d770bd702c29a42d4e9b2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/git@sha256:cb9b70017b3ff00b70463f13426fbe3f3bc5a52386f338ff746ae6456776b41a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/git@sha256:eed7441abc75e03e98850814ac847a4d8cb2986e1ba83b6f4e19f0f8a539dee7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/git@sha256:54abfcb02e6e03806a5d743be7fc78adf185600fd54052952e81e1f2e5133d1f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/git@sha256:d55097d508eeb44c835192387f9210822754ac866f9e02ea78976ed5faf8e024 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/git@sha256:1159b6a1fa12a2d6270227f48390f0cef168bff84c6c63db0c1b577a52669686 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/git@sha256:542b5c613372202bacc09f8d89de3a37313d3932a4c911544e5e40597bc813ed |