Sign inSign up
Git

dhi.io/git

Git 2.x

CIS
linux/amd64
alpine 3.23
Tags:

2-alpine3.23, 2.55-alpine3.23, 2.55.0-alpine3.23

Index digest:

sha256:9e2af60f63924bdb227e6825442eaad47328400e7e6ec30d88555078842b5e4e

Manifest digest:

sha256:036c5d6eaefc6de7a7220aa7912fab0be0907c521025fe9ff19986b82c92cc85

Size

12.73 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:f915a3bbfc15feffd9e54224b2715cea1670e4ba0429ce7eec6fe40b0092a14a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:7b782b413577fd6fefcb62f878d116727a05f8324588edf8f0d1fba62b7adbc1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:deb68417910581d69029b9e0949e4943ab426433e2cdaca0f546cfec0c4676e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:964e090c57b68cd3dd1d41adfe15873d6223d19878be037909ffe9a03d15a9b7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:e0498177094e40754bea7e69f4dc12aed96696bc08d852fcf12dad7f4f55351c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:a2e050be8ecdc7ca5264d5d8f5f1dc9e414747ebcad49e51424f4beb9196ddf6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:19d7cbfff57a33b82c5a259ac85c5e9b8d439837e428e42eea9fca95bb8e6f0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:98f18567038df03af4ea1719c7b49638f460112c292a45191bfe442ad312d77d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:0894088027d58209020abb4c6f8be1e373f978453666f3b7c58758bf72a9ee13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:b3989c6c345dcec728a926712e686c116aace4e382b2788af930fe9a2f5b055f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:8c5f0512b71fd330683e5a175f5a9826987684b0c96325eab2b493825641fd0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:c1693ad04ed7bb06af0fc2bce521579fdde7e60a97e02e24d145e6491ac7b6ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:1775f52adbf02fbd0108cd916df92aa8d75ad2f2e1ca1bfbc0694a8dc57273ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:76b94c54c1257bfbdb6b201e560256e7592f6856a880051b27b3984994321c61
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:53d879c026776aae019c773396f2501d9a31b27b1ef58f82331ee019b5385593