Sign inSign up
Git

dhi.io/git

Git 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.55-alpine-dev, 2.55-alpine3.24-dev, 2.55.0-alpine-dev, 2.55.0-alpine3.24-dev

Index digest:

sha256:f55491f6fa552a3395d9308ee4de30c3d98236e28dcd01188ef25a5afa60e516

Manifest digest:

sha256:2c2e43c6cf4592c99646a2edb59e4d25caff55a666e555186289b21e177bd19f

Size

14.85 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:e6561d0fb03ca33cd0ef3a4b06ad2bbb87fe36fe57463ceff3f49c631d71b850
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:69433b70d25eaea47374cdf5e3ce14e34a7f40c0cea49e06aa1b30f4ff240d8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:dbbd9e0e0d5d0e2a57430a02262f0bf21b0d7d62c88de69c67adcfdc27f04d73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:3063d37c6e1a9d9b519abdb45b2229d484a7cafb5cfb33e78c5cd89928781bbb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:a5e7b8507de10b73579964d1bc71e60febb098f48063e355eda3d4c433f62d18
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:1ced5033b40e28a70b9ffea9f32db84caa72e17e744bc0f4f234a0ff9edceab7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:a5cd11b88df077c9338d666cfd1a4ad41a805e2acbbf5a52889fb20920c9f880
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:db890e6c2c3070e7b0cd05166e723bd9239aaabd4d304ecf6d7971e160fb18df
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:ce3b4b41be3441eed9bcb0f5721fa169c40a44abf48839d5ac8a27211f07b9ae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:3a8e79b5e03e767afee10f012414019d7bfac2a5d134154692fb07bb03e03caf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:65d5f10dacf266e5e0cc2c79243c858c3a20a8464766ccc4adff5d3ece129f16
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:5f372f21fa7300e4bf01a0540d72bf487ae15f6a3ab32da73d4ac3dd9e4605dc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:11ea9b4da83094d2a3163eed6f579a76c2d2b7936f1e124cfaffbce825788b3b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:684a7ab649efc879e0ec5d4d1633d845416afa1da4fe1ba4df640d8dc1419f74
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:f8a0ce478f9db4591fa5e944890a390e063c7f83d2813f0270f205ce24cd1609