Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips-dev, 29-alpine3.24-fips-dev, 29.8-alpine-fips-dev, 29.8-alpine3.24-fips-dev, 29.8.2-alpine-fips-dev, 29.8.2-alpine3.24-fips-dev

Index digest:

sha256:62a782c3e25028f9ad9a50f43651209b6a6c8af342c6d1c1353fdb7e805d9313

Manifest digest:

sha256:7cac91b8d4caa78f05cd2cec93ea6b4d71e4476cbf777b7c30f45e9068e50a64

Size

103.47 MB

Last pushed

1 hour ago

Vulnerabilities

1
1
5
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:d1f065495771aede00cb21c79694780bd52e710efac7eea9b1bae48869b4d10f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:f5cf63531ccc93e84ae965aa5520cf02950401e29f0d38e0d47ff1ef4adb558c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:6b8016cce648f1e318dd6e548f8f5aa7dabfb991a5992e2b26c13f4feb474068
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:e97e5733c28c6e0fc3decc337e2106bbfcc3e8d9fc6ddba66efe1522a988b1f8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:761875be081daee046b81b5ee002814a8996dad64436d275ecd79d0818455b4f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:20f4824e353d12c3f1b1e82288302305d2b1e9254c3c59e90bd054867bf985c4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:2dfe1b1ffb27ef62c0ca052d14677c83cb0dc119113112673e4983f44c2e4948
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:a89d0f9a71d7d52bd134fa3a983ca74318a29a9220ef240cfee7e3dbec362731
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:6aec4ed858d944141908dfb0484b72b8419d6fe0974a493ea469d501e33d690d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:0741ea61016cc33cde0c2340172c204340d523edb3458077c20e621b70877197
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:20ab9d5f1fc8574015e9e1e89a3d2130c8350125363cb99ecd0a8226d54534e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:bd3ff722290cdc5026c142e0395c4f66635ba50fd0bb36c23b85a598fd1e4ca5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:daeb528e6c41de9ec6130fafd0b3c14c035b02b22021ea13de1284f58d0e6b5a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:3eec8f143fbb0d9f120d34bd19ea6f4bec5a1b90031ffef83caf3e9213e3bd24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:1642dcad89bdfb08d691f114522c38a7e5e46d60f5df14721703a2d3d5541e0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:c5134227b13639895d8fd517080bedc8a291ed72dcaffd091f75ba9fa84f0038
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:e50fe0691430f0848bbff8717e50535efbe443672c0dfff82473ecbea9eb95b9