Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips, 2.56-alpine3.23-fips, 2.56.0-alpine3.23-fips

Index digest:

sha256:d35a4374d088eb2edf5ef9716cca78a0710bc66fd4ef6d2d8b1f9c87f3998b05

Manifest digest:

sha256:93503f3b98a6d48698ecf0cbb6ea435976086332d9e65b5a382fb4f4aee12610

Size

13.95 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:f52efa7ada07804eaec62451defbc04246c10dc246709cf78f048ce143cce1ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:2b3e51ff7ecb13db565108d86c86c7e7c2f44f63a2c5be5eafe5996a102ce3ec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:e240e0c55d5aa1ee38ff3b14785709357a393ee70e98a9b656af02697277133d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:f0841d91b3b4100822bc16f57254492c67dcc43d2060b5e16c9e0475eac9a1bd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:398d33215bd1ff71a485a2ce52f85f8a17d1c316eeccafdcf2174dd2bf88802e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:08bb948565ecf7b0b772331c29547837a8e1f9a05730db3145988686ecd7df8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:9bf7a85febc48f99b15546edfb53d8da3254b3342bb7600e1266b5984eb9df08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:1d2f36ec123e9a4e2b08bedc6a1d7ec1ddf67fee55e0d3ad408616152186faf0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:8e5693cda1603b3f5f85362d29a5aa7585b5f3b16d82638b87cbe5b17964d178
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:cf10e0150e2f77a5090385dab8354e9b9b2d85733bc1c2ef342ffbe0e0a691bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:d7ba675f9e4c8720eb180bcb0622f4eb676d08d6cf56eed12c2ee30cba5084e9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:9d7d796f715a392f8ca59e986339a5c5c35270a47c2859463522c5d8a032b348
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:d45a986a5cce9447bddb082ecbf40d3585ae779bc65c954c0c65c194d28f435b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:df74df1668759f485c23b592401a9efc07a72675ec91e26e4779a784d7e30aa5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:dd2af52c979347f4a1cd35aeeddb1fc83235f381f776868302d91a4ff61cef2b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:541923cc5cfcc49a86b2a7adfb0b1ec8047e9783afd45999b4bdbba2979a57de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:c3d7f65ac2a65e4c1452622f0677d1dc99c02bb51fd0bdf714544d61d87e9121