Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips, 2.56-alpine3.23-fips, 2.56.0-alpine3.23-fips

Index digest:

sha256:a360410fc89d1e8320d36da333f66a20824dff94eda631ca36543d5eab640596

Manifest digest:

sha256:7b28fdaa505f0e4a57e7b2f5a7ff881c81fb5f02d3cb860ba216aa458682cbfd

Size

13.95 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:dff2d3d9630d10a43834da46fa9fdba81dd24449c63bd363841d67697491d35d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:c037fcdb7668ab7448215128ac2fd089665fcf12111c99ad378aad66b5c12ce9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:a59845cad2266ac443fc0f1f62dcee89aca05873b62a9772763727f6eea598f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:3031f6ac37157274979857968bc4cbdb5534ef8799af64c399d35978d64e51ed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:4d16cc96951958202ca55c8812e0decf1bb6de436ade6364a0a74b44ca2a5eeb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:5d5676931bdf5cb6cfea6602455e20f7bdb144ddf2a3eb1b0c48b2536e748854
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:b413cf8f4fe062159dc3b8b44e84bf57f1570d3f65e0b5e138f0ec6210af10de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:a88d6166b43653dc348025f3f8a7a5a8a6f4b9325f3577289cd0c7f78d95c5eb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:e505935fee340b757473f9f6a9cda3b86ea0cc32770a54fb37a5ff191a293097
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:03b44a157d22f2d0664d84ee6626dd42a07bb143f93f0358ecf69565f1a25a08
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:517245e9b76074e5dc0af57009a5c8438024142f554c5befaccfc70161bba7b9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:d41c33c39e306b8a24d0904bd72123a35edd87d5f923948af9001b8282300038
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:b18980b09dc5ca03c7433ad84f52a880beb58914f8964d941317a246afe7cd05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:acf87182ee9df548ad16cf2097eea47e4b3e93167c19d83f16ef1fbf55f99707
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:105dd3d2ecdf70cc29885c46f564ecf41ff322e09c484a89d23140dd387fef70
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:0f70c362261706d6406205b9fec5d74cbc3bc8db3a407aea5283f0019c48f49d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:6af6cca8272498635ea85e464f5797887c6d380bc85d15702d9bec79ebef2fde