Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.27-alpine-fips-dev, 1.27-alpine3.24-fips-dev, 1.27.3-alpine-fips-dev, 1.27.3-alpine3.24-fips-dev

Index digest:

sha256:639abc65a7dcb8acccb7608fdcc0b2fe076543235c72e13f050d213a66abb9a4

Manifest digest:

sha256:a195061c986fb949aa085ce539a5ad3ded63e651f51f29a467da3c1c592b349b

Size

89.82 MB

Last pushed

11 hours ago

Vulnerabilities

2
8
1
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:4286a8e4daf2b5750861dcf44fd2c3371aad5b1c06d73c475d471c2851bcd0eb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:1269ccd43f7f24b77f515393c59b41aebf6710a81e95c8683ec9d449c77d3fcb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitea@sha256:da432e7850a152dca7e2c639271e12cc32a1bb0699eea2cb5570d49b246c2ff7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:92e6fee3dcf4bb2085577a8d3fc4ad3642477d70b69fe63871faff2e4015a72e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitea@sha256:2918c38e748dee752409ade24c81d05b8c828040796a2b8d917cbd5ec05ede38
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:d9faf799b35701985f5d49fc25557a2e746fb9191b4d750912516dc85f3faf47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:e14b00af53ec78b4dfae8fb4f9db738269f2f9f4abf2edead8f0f08fa178f40b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:a7fa6b5334d6c434699f28cc8ca9cd25f809b734f2c6b649997515ba5a7eee4f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:b27b1d26638e6c18a527862fd9b1dd549d0d3bdcdfeaec2a0f7e43b92e39dd6d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:912857ac7fda93c07c6e6bb7d66a1d35ac17d095d373ddbcb045de0c810dad5e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:8e654ec9b8a83ee5d4e82f94ccc485f76f3d1b9dba174c43a3042cb008a4c798
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:002b6a295ec247df4e659607aab2397e5c77f750f8c58b1fbee098c8a1d525d8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:e4d73883ee227b506f74c3825d05bd6f102893fd4624e3d5f200263a4d5bc1aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:4112273c30c10e28a1862046b4441b8a3155ada5516ffa21c4bd39359bd4230c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:823e104e11284488489ebf80205aeffcd8ab0e33a34381011fe61c756c1ae833
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:1e942d9c45e5e70da9ee926e6f6bb94ae70538977e36e14d07fb55957b512097
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:9e9d99bebf6486505949bd2687b009e6c15251f7acdde6a59888c0bbd680063d