Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.55-alpine-fips-dev, 2.55-alpine3.24-fips-dev, 2.55.0-alpine-fips-dev, 2.55.0-alpine3.24-fips-dev

Index digest:

sha256:75e7179ed66f8fe36c5c8f04913c2da0b719ce24d3ccc6219643d9897ca2d908

Manifest digest:

sha256:db7561a053de8c72ad4557d2230c2f30257cb39ca17e143a1bc51386fbea484a

Size

16.02 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:fd40b800d2a8e93c533537cb349e9bcb28569e2af32196dbf6872fe2e2b0785f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:2803f0015f2f1c9f01f746a8c5b18f966ac428e5db35916d6a762419e0c28e73
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:ca341fd2f3a6f0255b87a66be494957267d06b2b67e1475f01c5e5220a539c92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:f76e35c1ef612a71c989c3be7dd16270868572c16c6572188a5c9530f64fe2d1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:5a070086666ecba68b01fc2f991e6c10a6397cf27fba90dec86b8c9bc146a891
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:6ebfb6d499bd03e1636543c9cb42f54f1d17ec9c8798b7e635af48384782cd0e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:9c0f9be1c0ca5de04a1d02a9c64c1405e4fd399bfcabb41f3318ecdb56926edb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:2dc2094aff172b4cd09fd1d9ac6b6391c15e15467f737d61cdce4b443365c389
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:b16da3e6211c1f26336edf68f6ada446e3cffafef882a045c4226d8cb0e5f072
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:029b0c1218764a4dc52e2014dca1c529b4252f23e1bd3afe0d55754cebc0aaa5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:e680ca7331b8f12ccba940f788b52d90245035ecb60755df7a185ed7a58cc0dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:15a152ca3fb74ddd0cdec97a41a0665fb52560256e30138d75ccace2945e7124
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:396313aa24e4b71ad0e2257c6016b48db5936689374e5d1f9c78ddf9b25949ab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:8025cf7e8715e3c9d4eefc51e2d6dd2e0181a084950cfdf18c75743addc7620e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:b0205b195284b9846da84601cebcc6ad01c2046c389d70224a992ccfeb8f981a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:58f29168a8f94d5fd5fe06f78457e0a44a2841a943902711e04e774c20388e36
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:58c3b7621b66211aa772c3565f9b013c29df8a0067d9939e00f5727f6f29c66e