Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.55-alpine-fips-dev, 2.55-alpine3.24-fips-dev, 2.55.0-alpine-fips-dev, 2.55.0-alpine3.24-fips-dev

Index digest:

sha256:31bae521cdbcebd71419555ae95dd0d8c0f84d731e1766aa30ef10bd120b1ade

Manifest digest:

sha256:bb2d5300e1b87ff5f729ce2d954f4b5260174e12b51c010e4ab15dd71b7a103d

Size

16.00 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:49a70f309c1c42154928b7b04b8d047895e6732c60f6f7ef07c6391d464fad83
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:f4a02e024f6c436bda44ec6ab8d05ea6d9261f8fdde56ad524031286a8654eac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:88a0418dc17b4038d33d51689f7cad58e9e3f5321d3240112c6f425ca8533fe0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:29f74c53645200dda6a5fa66d53a6cd79aafc4cd7f8578d8e647327462864f19
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:cabcb8f521cb67e63a40271d38ac5368b837222b00ad96a62d9e9913473b99c1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:b3aa9e8e478e0925f569d179e860111ea9b842db62ad2189b193826581bb2774
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:c80d7f28d1efbb45da5f350dadf4ac1c4aba7454a22c86ba8970cb48b045dd23
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:a3ef34ed76e15f9477ad38b8091cc13d0a5e28fb8ecd0ca926daf4e6be517349
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:3261376843a14b2c4b0369024b8b549f395ab356ec94e9ddcfee0febfaee5e4b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:e7e757c51c892a7c06eda32574a2a8e29952c12ee7ff16666c6fc84b63e6256b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:472b948d258642c2b060e0ed2b4fc4f1374cfc5283c2804b9c3cee42e2fa8426
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:1ef7ae0eeafcea66162843f7373427227c4c584dfe2fd053a493f63efd67000c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:4986330a8843602ae19e6017fb3401d548e5ebff9694375af7d1276a420f47e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:9aa26316f0aa5f25b4a9685cf3d3893f287fb8d1e36ad74171587f44f794dd5a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:841463a3be4fa573b2f4d5b631ea760abe523c581a0b218921c5091414d44e01
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:0301f0208bc02606d7dbed153a6a91b7a1b1ce90bcec47934b97fd230eba8d58
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:160f24a26aef42a22cd1a7f0d1d59046b77ee9da86cd2f4f120c842e94fd328c