dhi.io/fetch-mcp
2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest
sha256:5a159e9cecb7c2d72f084dc493785a2dfa5e0e64e3f1d4fbbc789e705bc37d0e
Manifest digest:sha256:afcdf7e0639becc9871067f5de1692ac565e8fdd27280f4f218581b22d94d1ef
Size
31.09 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fetch-mcp:20262. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fetch-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fetch-mcp@sha256:5fbec9d4b54b5e44a473b832e48cf71e629f7d363864a98b871d73f554a522b8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fetch-mcp@sha256:d451720773cfa1dd985c46b00489c772980702957cb479aed2fce5526062260b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fetch-mcp@sha256:093bacde18cada62c9daaedebe0d7b8cc667df0d0dd39d751eedb132e73d5056 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fetch-mcp@sha256:133bf1c50165d73c38c16377e4a1d546e510d5593188c6697533f970364fdab3 |
| MCP server.json v1 | https://modelcontextprotocol.io/server.json/v1 | dhi.io/fetch-mcp@sha256:03935e233ce38d6e15c73b20755f63393f82ef975b8e967be287e8ac184e72dd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fetch-mcp@sha256:cea9c0210f8f41003a5eb17fe3c7738930cf53280023ccd366905cab0c790d18 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fetch-mcp@sha256:f1f9141b4865c0d99ce12effb07b1ba21d0beb7c1754e930ace7a12e96ab72a9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fetch-mcp@sha256:4ebeb95d7db4b600087f4c5bdb3ff549c6c50006082d7a9e23e137418cb076fe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fetch-mcp@sha256:cc8d52e2e8f75786603a8ce4d19007d9158766780c09549a74498f62cef8b9f6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fetch-mcp@sha256:edff20141c77092000c0918ff65f51a091c1ca62fcad1ad917bb6ac82b75a6e0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fetch-mcp@sha256:23ed92116aec58011e265b36a6ae58e00ec4abe3a650dde1eaaec94038923d2f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fetch-mcp@sha256:be9f9b42667bc4c67413f365caf880d785c169df0c7bcc6c43b54b0423c25737 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fetch-mcp@sha256:60f928f1cafeb7f700033db8ed2fb0b7e5437b3ea16a5382c16458baaf361623 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fetch-mcp@sha256:1cbf525a611cccb1f9c08bafa96d5af0c78fb49931184732842cd9e5ff3f25f3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fetch-mcp@sha256:e2f4530e5ea20558ac9057518a113be09a5be9028e16d7208f8a18173dde540d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fetch-mcp@sha256:ce3d34dc637d402de8a7867c80b1fdbb743d9091c528d3948f58da9efc355273 |