dhi.io/fetch-mcp
2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest
sha256:06a32596266953f797a1d66c7fb3490c6b3b9341db53b9f2f1ea1dbf3e7cfd00
Manifest digest:sha256:6f4e4f288b0627feb7aec667ef20afbd1c8af9b39821eabaac2e341498ed18c6
Size
31.21 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fetch-mcp:20262. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fetch-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fetch-mcp@sha256:96d95b541dbe71ac71eae8c588b2e6bce2793034140327c07420fec980957513 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fetch-mcp@sha256:c90d981e87cdd5e9903d3c2a27ec4152ac8a5fbe6c2b74ecf28f1a53cf078e42 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fetch-mcp@sha256:60d2a8abf5f946b2d819ae5aa88d9dab1f61a559927a95c38f2106d494dd0217 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fetch-mcp@sha256:9af5607cca2ed2bd59509a8288aae065cb6c04fb2f00b7c284e0d1cacfa62287 |
| MCP server.json v1 | https://modelcontextprotocol.io/server.json/v1 | dhi.io/fetch-mcp@sha256:19f473afdfb8a0952a2d2db2ceb3d5f05868e1f3011ba725b468007103c27b2b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fetch-mcp@sha256:3b72bc1e988c31db54054b39df3e7118625d18df0675168b8e1225dbaea86ff7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fetch-mcp@sha256:1c8c35099ee0129f6e60ed39c02308512fcbbc7c32ffa13eb42f001f9dad4c07 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fetch-mcp@sha256:4b309495d36eaaa6701720692fcbfe0a5eba7c8fbdafa720453a5106aeaa23a5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fetch-mcp@sha256:f402b10eb5567522563327f037b931ddffb950f911d73e5b9c1430a2627324ba |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fetch-mcp@sha256:585f20570a9730188a65e5aaf60bb297938f7146ad5535cb072ae64236fc8a36 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fetch-mcp@sha256:7c9dbb94d3fd82db492525377667cb1a473aa5a4d24b638f6eb8adaffb8bfde8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fetch-mcp@sha256:ad080ff41b1a1e26162530feed06d303fb9ac0291833a8d3aa8d75e48fc2628a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fetch-mcp@sha256:74dd331d9301ce90fc4ac9a61a8e334cfa40af6ff938c46240eb04ca841f3a47 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fetch-mcp@sha256:096da9c2f7094b3c5a82139f4735f56e1f5a14b6b56932d00af4fab6271a1047 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fetch-mcp@sha256:17999c31aab0ed1dab9551fe4dd8ade150923327fc727b9e08b8072fe9f1a5c4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fetch-mcp@sha256:eec87149fd9eef88eac9f48f442b74c71573254aaaf308d5985b002ca206d83e |