Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.47-debian-fips-dev, 2.47-debian13-fips-dev, 2.47-fips-dev, 2.47.3-debian-fips-dev, 2.47.3-debian13-fips-dev, 2.47.3-fips-dev

Index digest:

sha256:dfbcd5986995415babd7e48eaef8ab82d74eab18307fe249be17bff7047e33e5

Manifest digest:

sha256:8d8d6b25a2d597b83f7fa3f825cd402facc8eaefb9faa08d15f170b0a32d03d2

Size

51.49 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:c118298ef52713c542774a29d22a98acced8217c51006150e67edc115b896f94
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:bbac28beb5af81dda0c9b124d5e372213e4a8048b94667602dac124b5d379700
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:b56c2f16f5b8f32a5aba3077e2b3640ee7dcdd6fc33fb3e7df66ef5594543ef8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:3f6ee6eadc8d67960e23299e216653196f66655a96de21fbf60f99697c3d6d77
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:5011cc4bfdf0d45d61a50da144926335473b97dd01a0c3c503612b6f2d7a7ac1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:d96bbdaf9a51caa126345bc9f82f4723c4ecca54dde0f992d6ce321dc6bcdc3a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:9857371711e740fe0c40ee1416c7613cede5a4ffb03e6d59bcd4510abd7ad238
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:368862664949869dcab5a927f620b06e7ff7acd312739ea33942747d32042f18
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:5ed9d32c0834ddb3a29ecf28484c2773cb78ead8092ef3526183225447c6b362
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:2a8a9e3b80de7018990e42663dea577fbeb6f550c0a82c4a7dd3166c92e41aea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:6c46d80d548b45aba7a8fa73cfad2e3b4bd95a867c9fb928557d782100cf65a1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:ddf5a65847669327452a1b6d6144b517141b22c9ce20c22306fab743f04dc5c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:5bf5937984fb969595b28bdfe0063d53bd608843ceb9c15ef7cdd5d688b5a94d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:8364c75a4a5df65a86f4d95f8fb19a1483762737fee77b0d0c285f4cb43fe4b3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:442355a2364aa04acefad7bec8645d54257ffdd76229b890f4a11b5365273322
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:c021f393be3d14cfa42c64038194e1e5b2e765edce392520a7c8536d665d3bf1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:83300c38f9a537e5abafe3c3494ec80948c5166c8df3421902713df116f72b16