Sign inSign up
Git MCP Server

dhi.io/git-mcp

Git MCP Server 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest

Index digest:

sha256:2d77749f204dcca987ecb7ca4bf78ae799f5997ed76a0c9e8640d6aede59b00f

Manifest digest:

sha256:d9e6dab84aa47df9da7e070b43bee1ec735452b5de29110b276b9b8a203f2ed6

Size

48.08 MB

Last pushed

13 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-mcp:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-mcp@sha256:4bfe21aaf8c0161ff4e619d85f6759f7d1df4133b29d3f0a7473e9558ad2eb85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-mcp@sha256:881a31db0f9f8f1ca7c542a6725b99a88fb771339fbd00a286041e4fcdfd74f1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-mcp@sha256:1716003283c2fe4e5de77b482992d93725c8a1ea17f044ee0e4c5308cef60695
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-mcp@sha256:5ba296915f28ba5043d86147314c861bd8fa2141c9d2df7ed87d68ded97657d9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-mcp@sha256:d0dc48e32a298e6e29e3f66e90f5b5c1d17a989cc9496bf57699141c0861eaf8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-mcp@sha256:4827eb2fee3656691ab7e1d9f84b317206806c77aff480518f2e9463f77449fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-mcp@sha256:ad7e1497b548af165603bb8b8ea8128a217de2526c9306b45603c5b151968e37
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-mcp@sha256:97a72fb9299e40a51eef344146feca6401fe663b544591f53ce1a9293a205dbb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-mcp@sha256:78b7b28a7cb355d61656a2821f10f2c22e8fb7ae3cceae151e34a8439697aa30
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-mcp@sha256:0a4070b928bfc3d00415d034e651c111388db84301f20bf38f1a52c3b696ebef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-mcp@sha256:9cef072d36bbd191fdfdf78e4774c7ac8c69db0e7163c5c5129abb20b48f7e0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-mcp@sha256:cc9b68e01b686711fa7fee4eeac0b70ccd6d4d3477ec79b9f1918149138b5fc7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-mcp@sha256:87d6b3a0f0fa6a1cb6538bdac0c61cb1324dd1f94139ae13ea51910685ed8fa8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-mcp@sha256:1ab9b8fdd4be9ad71ec9ac6650631f20bad19df0292db967ea09f7cc0aa91182
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-mcp@sha256:a253109bb575485c976fbd6ebfc555c3f867985c19d333592440d0b70f56d036