Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips, 2.56-alpine3.23-fips, 2.56.0-alpine3.23-fips

Index digest:

sha256:d22ab8d11345387194aed8593dab5ca08771381492c4e13995d2d6528bc55953

Manifest digest:

sha256:eee090fe26471d9f35911d62f158ec929115cfc38e716048ef2d4da570e7e682

Size

13.95 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:04860c07312824a140f1e82139818f6917c33f77ebea721552381e1870675721
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:a85d2ec356afc7aba5ad75ab068ba5677335520bffaceee845555f019ca41464
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:74310b7ae6a87c7712b24e0530cfb19f201bbe45d2b6544ce8d02d3d3cecd848
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:89530c1d16a49c9694b9cbb28821c2d3b15972516113e89be57234e708b3f331
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:2f74d81696e25e810263445287ace02f250b2bdf712663bd4b44133af383e3d0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:265c99152896f38ec180a42ccd7b3a22b95fe6f7c113e65ed8917757d6e74519
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:a4ccb5c21a2f2d8a0de5d1ef22eab261791f80c90c8e082fa8325ed2acd1af35
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:39b0f8252d7451813e4ed52dc9c4045a1d03ead72a5a4fe15e5af923a577df4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:8687b7711b9a78a9ec87e2d506c97254cb728c6f88fa07fbd11b80309a42163e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:7a54eab08f3625f0faaa0c2464aeabdc8eff57a174b90c454468985569d81bfc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:7fad261ae302b5f972adfac3c1ee06c2fa4f88878d8bd8c970f8e49bc0e94401
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:462de4a5d1f4b9635bbc02e77bc096e73df1811f5b6e8aba57cd316289c9a8c4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:d3a9ba9f3871cd8f3e4363cc84066a2fba969e6aef1a22abb0597dbe56f9c16b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:420943078fe3f40b694967c4add6d1ac1ba429bec7bc91affaa2f420dc768325
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:fa94d199358c584d29a4962da0016d66d3deb6efd4860b97b25574e49d3b424b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:7ff046cffd77baf22e2fbfec0eb03e4faa856060cad2e1df91ac8b8b113d8d69
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:42cd46443cb41933f5dba52a3dc50a51d9d9f73ac4b4c1c945c5784c5858fa29