Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips-dev, 29-alpine3.24-fips-dev, 29.8-alpine-fips-dev, 29.8-alpine3.24-fips-dev, 29.8.1-alpine-fips-dev, 29.8.1-alpine3.24-fips-dev

Index digest:

sha256:5fb36a4f8904a370e206bab361e8a144b4722a27876b79df92eeea1ffa99244c

Manifest digest:

sha256:2096d1dfded1c05c44c084b4788d548c8c8e87ac655efce5bdf7a001dc115fa6

Size

103.63 MB

Last pushed

5 hours ago

Vulnerabilities

1
1
7
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:78ee1efa8a7e6d3ba426311f0fdff67ac882f9a766bc104d109820f7cb9a36fc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:a441f9d7693be6ec277ebd3d6eae3d1b4137890a7ffb88f2c78daef32b749113
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:641a8a5789c12eb77b1adcd59299db5268f1c31a4aa9919288dc6380ddef414e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:3681f8ff885bfa534c5acec9c4edacd3eeeec71dc3dc1ea509a58c10f8b2d465
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:f5caf1c7c7982c9c7463edcbfb422e933b67cb47918ea8bbb62292ed67ad54b2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:c596bbc936fae557138fc181ea7c466fad088a9d5e8aaaad79b2945c03320823
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:3400a8f95abe4c53cae5bee9b41ddd72df7bc3f2bd29b088b3756636e079a466
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:d4439f812fe63f42cb76e1654b47002ed3276152832151a64a0493d07e5fe5d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:908d3756014412f288062bcef5918ba6b8ce8a427460d4eebd9e9fe994ac1195
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:8d9186ae54eff37e621035737445d30a73181f5bae62ab02b2d669d20f879170
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:d02550ff211476a26948728ed4c64b76e9fa164232ffecc72f3c9725dcae5a19
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:04c1b4a3ed343ea3129110f86e3c9123e4346f4d5fdddf9cb23ea4dbc3eac54c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:36cb58562da79eab3f6ae96745da332ff82d181684b478ee8425e93138439d26
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:81b12a1d1e2bf98805432820c5971c1b88aab74ad66ac5e9806710987647032f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:488320e1efb37a1928ec41e0dfd975edec8d50fae569d77038a1a094e779634b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:96ffebf037a7a689e8d88e0575ed8f09920d2816982cd3e242373666486973a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:e045f0dae1314b681aa43aa3422ce2103dcd77129d580d602c77b745a4c23ef2