Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.47-debian-fips, 2.47-debian13-fips, 2.47-fips, 2.47.3-debian-fips, 2.47.3-debian13-fips, 2.47.3-fips

Index digest:

sha256:badc3f8d4d6d9655f9f6b6848a7addc39dac9070f33f02044c90b871cea2d6b7

Manifest digest:

sha256:e0bc63984b6f529184a8461d709481f0e8567816ca291a267786f79fe2528d48

Size

38.39 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:9499aa938eb688b491c9406b07fba127f487166f7a961211410d84d7f6a3900f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:3b0e6187f724aad478137739b0de6b5d1cb4d8c8c98c5ae3acb772e9188db687
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:23daa06ccf36c2df20a1a7739e3e00bf769a3390df7197cdf627f5460a2bd59b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:97936558dd9b5d4f0c789bc8351ffd3bf0fe2b963e815984c018e51bbd7e20a9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:b35dc693ab4de4c6649929f674a8298df10ab4e1cd54596e66b6842ab33f6164
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:67165869953d342432698bef9125aaaf475ba128293d0ff86c78cc9efe91a3ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:54f2631b922351fdfbd644931db955e544dee18e75d730f2d90a85384516afa0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:44310ba5642666611f107b41076d0f7bb6814290bc4ba5ff4f1acb97149d005b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:7f3a84e3543e4e05516834884306d34db4469ea49ff55d42b1b012052ffef7c9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:bd2d04953703fd9333097109e1ec3d13efe68ce44190f2bd4b1202ca18a91014
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:81ee94ac92913b08226b3aa40cec8c60bd5937439b6d48a59d082200161565af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:68250caefbece2120214c4193d66ffd5195ef26b7311b6ef50c684decfd37416
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:be8b3a7fe401d92951922ff5dfe0153cc3b5cd6d928ee06f635716c6190206ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:398d2b93990105615d9d859b1e532ed60da2978b714d1dd505b84d1f7d17d9ea
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:a4916b944b092ba20489d458e0d6b7f918751cd883fdce85899f1b05f0a4f33e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:a4081cac6956a3f859e2ac76374e43e53e858bf7f441fd29529c235d02229f7e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:df09a3a0a058d69865be23db0242ac86062eee6283536b6074a049fd13ee119b