Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.27-alpine-fips, 1.27-alpine3.24-fips, 1.27.3-alpine-fips, 1.27.3-alpine3.24-fips

Index digest:

sha256:4ea4790391831dda1d0f9169085f01f526536d67ffa9b22fc64978acc4fced13

Manifest digest:

sha256:471de297af90ad3d3de843fd0fd9d69843664147a934a97651cde19084ed142f

Size

60.59 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:b0462bf67d7053c0b9037cc24e6d89625240830d6617eee64a64b421cc385367
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:7722ae13046553d621861218de90d7162e16c456b4d07d53c7fb5283d959df32
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitea@sha256:8528cb0ff6ddf5a947a14ff05903fd7d00e430ce5787afb5dd1d9453bc9664a0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:9b6f6290ded4b76d92bcf5fd6733ffbbe99ad0d933fec8e454286ce45e78d4bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitea@sha256:6748f7e75f0641a70b4c750c5fb524bc5df3c5d3f5e205d654a4f5814d9157c6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:0c8178602d805cd410e07277e81d607c1a3870cb5961651a7ed785b3f4ab1687
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:caa214eadb63015c7f39b4959a2e928815ac9233db5e7285d43353fee8dd7979
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:8587feb61a94900b0024a25ca609490bd1ec56ddb2634417f357cc567e46c9ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:cb4804a4a12f6a41fea2edc3bb8654e77e7b44c6c925ced65f9eea3f792798db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:2eb71beea9d343f92e32c770248e4e616abaef7390575c1bceff67a3dbfaeff2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:f7da3c73c633a98649833b15f6d0cb794b5d85a65efde1a45f091d842e264617
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:b09950d231208a2af79e245634d01cfa0f59d875a06bdede6d2b8491014aaffc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:10786ad9a497a2600e7603ef50d3e6a67fa7dbebf5bf7ddbd826b82d24b39b23
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:93a752bdcf725932234499ca529878cc900251be8304b0cf0c1b59d8e57f410a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:088c37f3d5f6eb6bb29a2dab6741e201fea3c04b3538ec65828b339b7b388a94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:89c93806adb209f4c66f6349edbc072772e2bddef29928b9cf068af5f296d866
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:347913dabb28cf604f77a599ea3937e167513813decac7c874d8679071bd9a75