Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.55-alpine-fips-dev, 2.55-alpine3.24-fips-dev, 2.55.0-alpine-fips-dev, 2.55.0-alpine3.24-fips-dev

Index digest:

sha256:0e6c559e7fba3f0d08caaa10a1059c1fa74b8e75bda9cc216f85a358c358aff0

Manifest digest:

sha256:5c72f2d139bccbb4acc045024b9da82e2f1f2c211d283386c5238d27a1e2e795

Size

16.02 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:a56680aa022663c73ccd5025342023464b3103beee90fd5521ab8781c1748edc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:e3a0e904619210683899356337369080192c65ee40bfab81bd1952a4e6bb0d00
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:fd52496097c62a7c74b5a2a2fea8169c42c256f6cbf6bd3f531318789c097d47
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:3573dba5a92dff65f71e2f6a067598e4a81f5d5970f3726748ab3cd6feb5e20b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:f109b59cca7516b248c0461f94718a42a313b471fa651ab6e9e68026d7c7ada0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:76c79b48c679f4e9704030a3e382837386b3bc90eeae957b7d1aa423222e6801
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:02b763ff54341391701f46233b594297ec02cab1d26371214cfb0585b6d025ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:921e3fba36eb1bae572fe4b20518778c0a6e7e622fa4f81c8a18ca6f9c286647
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:110b7f439e9f50f4399ea47b360412baf91b0012cbfe87e2ac58e66ca82621c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:499e8068084fff971798c0e76d036e807b04c112a5be99ed147ff734cecc37e9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:0b9570c63acc4f60276d62e9a11cf94c20b0225d74bb32b58d9eff6b8a619ecc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:7b7daeb28102e3012042b3d381d13668db08d47ebc4d37b6e505f2de4ee65ebb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:7e35efb1530a35e3c41da17f5e559418b03868b993ad62d45f7e747ed7831fd6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:da5fcde8ed0da34c11fcdb0089b72652282542f9c871e74ec99190b47771c3a6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:2e79e5be00ec9bd6bb9b4a34c391b10db346dc41a1c6a86dbd943a6738f23859
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:8c7b4ea031b35233877d56a24a349f1136ca446bc994c119f6af0acd913f3bc1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:d8fc3c681477dd4f83b9ca65404eca27624c82bec86ce8bfe1d61046e1a3ee84