Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

29-alpine-dev, 29-alpine3.24-dev, 29.8-alpine-dev, 29.8-alpine3.24-dev, 29.8.2-alpine-dev, 29.8.2-alpine3.24-dev

Index digest:

sha256:6e3ad3d06070539fe43b939289a32c4be8505c9c6a1eba0e7c96c627a3a2fdf0

Manifest digest:

sha256:f3e6762d0d407cf5c0d5c841a44e099e561616f7d142685103db3d29e503cef0

Size

102.62 MB

Last pushed

19 hours ago

Vulnerabilities

3
9
6
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:1561f0c187b96b8c8f57596025e9a9fc9228a87b50db628d0749984c12d277ed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:910ca7e0771bad2896b164c00dd557ae7a8e9d513e7f07d2982643af9cdfdafc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:7e0fc6a3035af9c0e22f410ad941de2f9ffd3dfa1e19511582430a0a507018f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:04e4ab34ff14ad151c3969be7aeb589427bc0695e6cf71456ebc395821b44236
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:b2c34f5d085585fe61c8c9430876bf2fd4852f5645b0f6451d2117716f68712d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:6b9bc796e4b5652fa47bdb57e87dbbd8c33751de6644cb5102d00075e7accc32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:8f7eee8ded9b2674fb3b901102045da4b4489836d9627387767757e18609377c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:15ae169ff0c036491e5e50b04731c0ba638b959114f70e0409c38db5f6fdcd86
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:829faacedabba07054079a6a8ac9a3bca2f6086f2d2a7391ef9c57d2f470af87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:88136612899e92c8b0e53d2bf23778ed070cc83d4aa044eb6ba5e983aed62d54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:d9b020ba7b09ae58ee5ef131266757a135be45b55930aeae5cf948bfccf50000
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:493e900b91c2c7b2d6eae5131062ee1d4e56a2c9e51643a4be7f42b2170298bf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:9ee7519a36381c27e3e74c1ca378535c57c549127547a7d43927d37754329c46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:dcdc9fc4b49468377e15868dbdaab4f865075a8fe2781aef014dbf78c8ad9fbb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:1555f9084f5d57b01f8efb617989f95bcaaf969b7ceb4f377fd9ce89016fe048