dhi.io/git
2-alpine-dev, 2-alpine3.24-dev, 2.55-alpine-dev, 2.55-alpine3.24-dev, 2.55.0-alpine-dev, 2.55.0-alpine3.24-dev
sha256:236f7c3faae4d343d4b3085bd922df81d9063585a849a12bf25d9449e900a8e2
Manifest digest:sha256:3e33a3cada9ceebd78562af2b1b3116c3c1221543f3d4b58242a901750fca4d7
Size
14.85 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/git:2-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/git:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/git@sha256:e04511356e126481fc779bb82be8738c6bcca34078f764149593adcd1323100f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/git@sha256:88317d801a3fb7d300ffa354e9c788b213e1ee34f0a54a5d46725c93bbb1db4e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/git@sha256:4ad636d0fb8f7581583b3139f3e48ab4fc8107a06bfc67e1d849853c54112b71 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/git@sha256:4ef8d59d444d201d71ca986da2ef75d483edd27c8c36fbeaa3da2b28861248c2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/git@sha256:e55875cccfbf60732125dd19328c26a6f10c26c999abeb5511aa190099b3bb89 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/git@sha256:3160f65fd8591069a8990056c51ae7a0bdfbceb28dd565c04d807b1544596971 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/git@sha256:a4b074f9978e05afdedf9c86861237df19ee6da5e8df038d8241cb662f53adc5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/git@sha256:70f309b5f4a7e32fc9c6e02dc5b56f8e92ef8166ffd4825e6dbb89e9ebfe6c37 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/git@sha256:3510140c0f55ca6a4ae72cad0cfd4074136aaee0519918c086af40e60511010f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/git@sha256:a9ab5c3aab109070bb9204ab4caf3e2e0750a4f862548fe474a1269ecfdc6267 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/git@sha256:94d742112c3f49f51a7ae1c9958b500f76f05463d7992ddd854bab962e364b37 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/git@sha256:07f237c4d6732e48ceab368e4c584cfd7918681388b807d77aa8a5c52c73ad82 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/git@sha256:cae213613bd6c6afb8f4186042b88ae399a6a25ddb243ec61a58b808b0a2aad5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/git@sha256:7ad38839569c1573b4926228fc77aba14524cb21a24dc7d352017c14ddc7ee6e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/git@sha256:c31f71e5b33fbcd51df1ec623962523f7db65f3ad0aee296a222a8ec64ffb507 |