Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x

CIS
linux/amd64
alpine 3.24
Tags:

29-alpine, 29-alpine3.24, 29.8-alpine, 29.8-alpine3.24, 29.8.2-alpine, 29.8.2-alpine3.24

Index digest:

sha256:d29596555914f3dfb08a70da01f9856d4d6fd56df24590ea808faf0b0dd2edc4

Manifest digest:

sha256:e28c25139fc41a89d272d8cd83bea5735dc25cb60ab070352ef3c63717233396

Size

101.16 MB

Last pushed

7 hours ago

Vulnerabilities

1
1
6
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:b594897d996719f36524d6b3b07abb6e5ab052badffa29988772b91dd2e14e13
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:d531ece2108cca526b55bf6d81b0393e94b81d637b71bc693e99cdebe0c68854
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:0cc20ab841d26fc6d1731e411e1884cf8dcb4514624cf5745dce9b6c760f712f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:a3a982d93d844a452af880a1b176047ee6d13f81ffd7ca40743b25510328df1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:04ba1c09091b565f95133af053fea48eb79eeab1d2dcbc77f6a68cb22681c1a3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:2c2f18f7a5eb0591fc00866f39a0d3331dba886d5d0c6d992fbd31bcd8fc8584
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:879c664fda534b989420189990762bd291143a8e5728926824dbc6de89f2cf91
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:868d4233522306e143bed6697ba078728109f83054a6237d5b5adebd654b0bef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:f4f398add96469126d9609d2dd857c0b8770ae92c1f57af6be35ffb5323c7e73
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:c52ca138e7c7a2787a414f88de9eb8e42262c78bf0218035a5fdda0da7dc4d06
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:cec111e1530d712b7407789f3fe14133e96a4b07405662af81f9c72af3631540
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:8bc05f3e1e0c2fc328deda4d5cf2868b9711c32ad1db7f09fb47b2157930fb42
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:771da4644a8a4abf6ccb04b72bf2e95f719f3c4aed50ad26085e550784aae1c0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:9ae33a78baa6d507f21f6d9737ec651e0c629f1500b98599b517969cc1b50d47
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:14391f04af3d0971a7888c82a5c8d824579c3e01341c36c1197d14e9c260dc70