Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips-dev, 29-alpine3.24-fips-dev, 29.8-alpine-fips-dev, 29.8-alpine3.24-fips-dev, 29.8.2-alpine-fips-dev, 29.8.2-alpine3.24-fips-dev

Index digest:

sha256:34842209a825014f9a6616dae624d2ef1dbabe86be240ce6ee6d5f9602f14720

Manifest digest:

sha256:bebae0549da4cfe9a0ed2acd736d927371f7f8437685d994c084f36de64a29ff

Size

103.46 MB

Last pushed

16 hours ago

Vulnerabilities

3
9
6
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:e9270b5abdbd56ed4ab8598775ec074a35a6355b23a71699d682521ba2969258
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:83c15b7b4a9a1a8d1cfa2832d6d96e62fb8e0f3928a76e8d632b4cf8d82fdc56
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:21910f25e6e1ba0cd7a336eef1bf2189139b4786a4c27ec72db105f93eebb2c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:e14bdc00b6a672ca913048b6b8d6e8ded7669b99930594e1a367df436ae55285
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:498abaf51836fb8789b0c7d872d25fa137fe58edfe8622b87e2ef7eca68f3a30
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:8b87e84a4325fad70c0342565f90ddd30fc350fb9246d23e3a32ecd595efa31a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:26bbac811dbbf8736dab8480c51950f9f08bcce94bce530d2d6ac9461cd43f6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:3bda220d25a853a154c47317d5d37c5f065e394ff08b66e635c178fcb936f55b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:78c6ceb232966a83908f5519149d6207857dd343cac853abe0d6518dc74b000d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:ba1f8838514468ca918109db41f050af31d935355a27ad08e30bdf55b2cf6ee3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:41939da281caac0a26b500d4bcabe892abb5a9ed87b48b3cec5f3d2ce9018a95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:8dfb9a0f087b9ec0ec05e9bdaad6ccbb27afcca85a5cd7a779aeae5eadb03894
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:289c08dc559d059272d6d90ba297862690fc90542e4577ff7e0939d5c998754c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:367759daaf3ab41cb230ba9b3b6a7425ad761235d41a9b02822f6e65da77b2b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:0a77d7b6c0a2c0e42c97d4477035b789f11699f5d4df27dbfceeb2e45bc39ddf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:5663c8c4d2b71a372d9b08400f3e00056e805e3ddaed1f0a48dc0cd38a1bf0ce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:7570efa9ad229de63fcb44ce575d8f0937c10dfcadf4c3b2eda0354dc5793f6e