Sign inSign up
Git MCP Server

dhi.io/git-mcp

Git MCP Server 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest

Index digest:

sha256:b9e860876c176384029af3e7c55569fc0de8ed8f9abedbcb56c8083fb052357b

Manifest digest:

sha256:9c4198fd9451e1df7d0840ba0bd5b03f476de1529f06b33443244a2fe4af6d1e

Size

48.09 MB

Last pushed

9 hours ago

Vulnerabilities

0
1
3
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-mcp:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-mcp@sha256:159af5a9f0778f7e3d80b0b9ea13dcaf7d9603b85cd020161f874c9ae4f36921
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-mcp@sha256:770fa0b887f8b7ac6e750c8047405d1ee39586dfa8bb7f66f1616c61d29dd2c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-mcp@sha256:3717b39ccf493b1a0eb1aef77af90512d658b9b57ab9ec5a9ebe4f9da6b30c05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-mcp@sha256:644f9ed0a717c5373963242244984ad9d9716e2d65eeacba87546bf8cd355b35
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-mcp@sha256:f590bfad9af64d387076b7a3df367e4fbf4c91fc5da45249a3138ae820bf920d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-mcp@sha256:86a79d109d7b6d7e9b5cb0524e97c87b7fce194f014a803d19558e79c75dbd95
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-mcp@sha256:c7544502550d45bc71700a075d6ced04d031140772108f1d6d382112ae498f46
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-mcp@sha256:a39575dd1efba6e99b69b1db84edbae867f31141202d2eea250d4593decd1c67
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-mcp@sha256:7df98d83d4edb2c250fb1af105758c92784fcee8b6f4f26a57d81ee50a911da0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-mcp@sha256:ce2e305d0b5f3e62371e3816c281cfbadd13a71f4d752422bb15521bcc4cfb37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-mcp@sha256:ee8b57585482fc412c8df7f73491022937eb3548a86fd7e452d41fe0737a43d9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-mcp@sha256:f09f5cb883859807c521fc4e77e70a10146690fdb10a541c6d92e6df70f6d289
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-mcp@sha256:3ef5e0b97b2cd5acff310258ba5538cd507786d9495d0267db150edf9de1f5d3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-mcp@sha256:8dc85a899720830e62210424280b99962defe63c7f791c0b030786c88e4fa360
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-mcp@sha256:fb5503640e4bdd6eb33e6e512bd9d8763fe6beef407ae49d79e362c6f5995246