Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x

CIS
linux/amd64
alpine 3.24
Tags:

29-alpine, 29-alpine3.24, 29.8-alpine, 29.8-alpine3.24, 29.8.1-alpine, 29.8.1-alpine3.24

Index digest:

sha256:7fb161a9a4b38f2126ea0952d69715643a5414f0dca864009133b23adc397d92

Manifest digest:

sha256:42d27198a64e76d98f3491fd6dc962a26acc905856cfa9455dc861bad8533ad4

Size

101.11 MB

Last pushed

14 hours ago

Vulnerabilities

1
1
7
2
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:8c4e9808a141a113f429216f6c65f2f93be78ff807ea18cba6c2a4fffdb496c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:8b6475c777e802d5d117884778167eca3e84acfc6e50b4e87278d2b4d8ece5e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:875e3113d4b016d5b981380a0ed8b5a6e83245a303a62f1fb917dbc0f5552e9c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:e9dd9aec3faaa3922ce694dc3fbd517496bf2e772709be0746a299c49d98e882
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:3d3415db5bb44ca6d72e34d6fbf3a139992b3a9431352f72ff8e4c74727b8d0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:9b1f0c2095a433382c7c3a5910047983624ebcd712d2dce0cca9567995ccd5bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:642f6677cdecfbb782f3f8692124a6d5b7418db0ef681d57cb6895bce8f797e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:1ba5e98500463382f47ba78cf3d29201a9ba2b43dc7f9bbb3d47d1718fd6c59f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:069dc5a8ed3703f345332a2e63b2abb621ee754b7dbe8449ee3b0eb05b37db57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:3d889c5e7d455cadcb114f38f9a8fbdce9f839a40f90332e1a14a168800fe270
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:931a4df0a271e561500b9a950f83c3aafd763bf31300161339b747b530ce102c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:c85b24e925b80c1ed95d165de32b01d3968a0092828f163a0160e269c8e00fab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:a6cdd35c68f79ca1a0a38d06cff34ffaa9105541fbebec64e3399a262939b9e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:af6e9be5a427138cc77f85441ef35afac601314a072c8c2d4575ff41750c5533
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:67f9b18a78c2b5e523b3423725c850510448130dbf0cfa7529d39474832bd5bd