Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.27-alpine, 1.27-alpine3.24, 1.27.3-alpine, 1.27.3-alpine3.24

Index digest:

sha256:0945912733d25ecc896ac35b709b9440f0655018507d384f3e26d5f8aa18c933

Manifest digest:

sha256:b81bec5f99a24beb8a98262ff4da3d39c37b1cbcf3822df3c120df468b2d90f5

Size

59.33 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:ce15a908e1b5e42a4acee3c3a88bd7bea32847c5669131554bb4c581e37e8a0d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:57fa8d87807230a401062014ed444f2d9c17efb5d4baacb44a861715812f01b8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:9572f11a9136e677759827c6cbbeeffa27009bad0132e8f64a3e5debe0cbb589
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:77908f72422bfc51b7c60e228bd2ccb5961221ae41dd29c08f850a08967096e7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:1c1e5cda6993454804631af91f7d61fb604e38ea86d6aa4fca56205652782629
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:e738ae44b864f12a7db1aa3dfbe4206abd55b27d00c5aeaa1afea050ea96ca9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:1bb5dc6184a0056f1d2c24aef4ab06bfd0ac7750b6fdccb1b972244ec2fa55f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:7c60bd4c9f9c3d8f78ce54790810b2e9b8dd496dcd40ddba744df0a08824a784
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:fb29cab25dda44d68a17bba30d09dcf7bd50f0ec74cc642248504316809dd37b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:d8492003a9fb947672fc90c353dc0bb94b3e2f067287fc0ea1de31c35fa297ee
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:b906aaea7a6fd95f07cf2fc0ed274af221ccf28ad63af5fb04e3ec4daa01740b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:f44d68c1f79f1b178eecc1dd3db40e81f4cdc92ede3b5ff7f5e0c598797034b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:ea8bd8c5ad183dc35acfeac1ca9802b5c11c79667101b9bd79eb606282c9fd08
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:6c74b5eb9b90f246208ff26881fcda8cbf0a3e3f6ee6d144d2115b6091ce2605
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:ae7aa2720e10b9b6c6a3a8657a3c078451f07bf91131fa9ced62447820dda6bd