Sign inSign up
Git

dhi.io/git

Git 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.55-alpine-dev, 2.55-alpine3.24-dev, 2.55.0-alpine-dev, 2.55.0-alpine3.24-dev

Index digest:

sha256:236f7c3faae4d343d4b3085bd922df81d9063585a849a12bf25d9449e900a8e2

Manifest digest:

sha256:3e33a3cada9ceebd78562af2b1b3116c3c1221543f3d4b58242a901750fca4d7

Size

14.85 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:e04511356e126481fc779bb82be8738c6bcca34078f764149593adcd1323100f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:88317d801a3fb7d300ffa354e9c788b213e1ee34f0a54a5d46725c93bbb1db4e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:4ad636d0fb8f7581583b3139f3e48ab4fc8107a06bfc67e1d849853c54112b71
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:4ef8d59d444d201d71ca986da2ef75d483edd27c8c36fbeaa3da2b28861248c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:e55875cccfbf60732125dd19328c26a6f10c26c999abeb5511aa190099b3bb89
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:3160f65fd8591069a8990056c51ae7a0bdfbceb28dd565c04d807b1544596971
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:a4b074f9978e05afdedf9c86861237df19ee6da5e8df038d8241cb662f53adc5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:70f309b5f4a7e32fc9c6e02dc5b56f8e92ef8166ffd4825e6dbb89e9ebfe6c37
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:3510140c0f55ca6a4ae72cad0cfd4074136aaee0519918c086af40e60511010f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:a9ab5c3aab109070bb9204ab4caf3e2e0750a4f862548fe474a1269ecfdc6267
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:94d742112c3f49f51a7ae1c9958b500f76f05463d7992ddd854bab962e364b37
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:07f237c4d6732e48ceab368e4c584cfd7918681388b807d77aa8a5c52c73ad82
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:cae213613bd6c6afb8f4186042b88ae399a6a25ddb243ec61a58b808b0a2aad5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:7ad38839569c1573b4926228fc77aba14524cb21a24dc7d352017c14ddc7ee6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:c31f71e5b33fbcd51df1ec623962523f7db65f3ad0aee296a222a8ec64ffb507