Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips, 2.56-alpine3.23-fips, 2.56.0-alpine3.23-fips

Index digest:

sha256:46509ef71f64b28504a40851f367760f1e93a1d925ffafb67aea07230c307e28

Manifest digest:

sha256:d33318f34f12722a86357bdc372d0bc72244b765ac6a007aff4231e5e6b41ce3

Size

13.95 MB

Last pushed

9 hours ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:bd5967ecd467b60c7d1a0a1337071b23c357bd7184d50d06f833bae1ffe12adc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:91a476b8d7c18856d53c9f6abf76f4d88c833e9ef4bed6c4f46498b51a0c404e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:6a0ea672b9d0606df1bb198568b6961fb7bc0b9c96074fc051206b9d18fd18cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:3520ccc5643b38a7759f0340299820f6115afbe1fabc88de5da6bcdd92397dbd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:6787f6224aba39f04f34a54ceaed639cd5ca0bf99f83765e2b25132920824451
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:ee9d0df4ddae1865ee3142c4e1b8b3051549f3530ef470ac377d25558320c9e8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:b7f2d641f87b0bfb996dfb4e0515eb42b6ff9a5ddab4d1b5f83e5dbc8046aa27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:bf6e05919d5425d9c7ebc56c221e5cb2a95b908b33f83f4da88965ad54e2ccb8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:c77b68d12dbd58311a89dd4f4cad2a4ec2a0d61c76efb18d82462a047e1a4dc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:e0c7fbc50262750876694c00135d296101853e05599e662c9a683d493a9d2797
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:f031d0882b65d1b17825d75dface3e0d2e2db51b5b143521e83fcc0889e465d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:6868b599b36a2529f5f6194742544256b26b0b3372473ad75cb1703801eaa94c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:b3a2b0a6471f76de1289ee3aaf656e4647f75c60b7ab18583caa7aea0018b036
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:90616f0b08331ecc99ba6dde10cf142da767da8efa49607810bc2694b8b1f247
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:fbcf8f07044774f0f0cb9f16a14fb1dd01283bd123b0d6ae85122953e371da99
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:e6d78f2f4dbe18af0320d485a08a82e2f6c97276985a47fcd1bf2cd8a8449151
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:e9a94b73d849fb154abf085a5ec18132d00c379e6605bd9a7cf9951bad8907fe