Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips-dev, 2.55-alpine3.23-fips-dev, 2.55.0-alpine3.23-fips-dev

Index digest:

sha256:8f4885b2daf37738d042d9e00f74800f845091359c678513cb31bc37511503ce

Manifest digest:

sha256:d5c7879824c3810650bb8a56ebbef2482bb1082cd8d80eabba1e40ad468ed7da

Size

15.96 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:95fe3ce04b0d72fa0993c087877796f86d8f1970287d6ce9da1ac5c5236635bf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:50f2699ba8894dd6792aea1bfbd805951cf0d971ca5c0f03f8d0bc6141c95f6f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:1ad7bad85e287f450936f3eb165b7ca712381e80edc884b249385888e620c850
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:9d3b4721d1ee2460e709faa63506705a850c85269efcecf00eeac96381c99e7b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:6b99746ff93fb0ad5f25a3ec6036ae38c614c56180e812c7010e83a447028151
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:a87c8346574586615d6b00681d21b335300f34baccd38147df5658fdec95d94a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:957a24327eba4ab783b68244c566edb7ef6206b9fb74d0f08c02e4e0d6d790f9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:83f897936ca0699a164cf29c8de5824493892abe82259f42d0070628c0ac4a40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:069ecbc922ac7227bf7562ca3023dfdb955451511a35b2544563606cdb653b86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:81982ff18b10dfbdc3dcccbcf436881edcdb1443a7f7de8904ef5932021f85a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:890250e6314f04216e5ebfdd170fbcd1c8bb20cd7847faeb7bb5434bef101288
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:0369e79109efaec71e386ceb2b249f0780261b4dc3b564df7ac58964d44def27
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:c2fcea64b1ef7ae8ebc56d22a08cd87ec1d1a1fd66e5846c4ca5c1864761273c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:50b2c6ebd72d0f212afa0524eff2c2141365d40f5af31b5d66869ce320d239f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:e262b5b10f7433feb406429f8ce511b7e65dc6e19502828724e4b2b39a8b6834
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:15aaf5226616976ec0d1cc349c4ce1610d55925749a8efeffec91fff227f7a93
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:827b22b1062a0412a39dd45e9b65a9e8e86f429d189692dc2d500efbae836f54