Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.47-debian-fips, 2.47-debian13-fips, 2.47-fips, 2.47.3-debian-fips, 2.47.3-debian13-fips, 2.47.3-fips

Index digest:

sha256:2a96125e5bf7973deca2ad13e482e8b7bea0f67e9020676fbd0a44c2cce0fc0a

Manifest digest:

sha256:0346590b6f3b4ee3feffbb2460299a32b015d6363bae3e93471961a40b75b2b5

Size

38.39 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:2cc15990a7404cda767d866120f8ad1ad43a1328818bf3958f70beaa051499d9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:8da376d2a92de1f522b60a1be57b7745f9ff94a46c6b4de20b8c5d0882c22ed1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:a193642f6210d759358b6a847ca6a2e49bfe2168c07d6ae17c8a3ce4bcbb6ce8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:3c07ef5901897db4ffb61e527da0d44b15232d8ef0cf6c3cb1d1994eeae25d53
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:4d02e76d149d5832d78dd5e2ae6bf073171d64fc51dba45009aec4c2c6e1ce49
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:e6cefc057cbb89e4f8349f384fdb583ca2fcb00032bee61a24cd557737ec55b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:0a7b5b110df6f7689b505bb272cb76a35bfad770dda01499ca8a32be9bd376cf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:83efbff873eca1d73d77be029dbb71c88d921e30a0c06b1395c9b1ddcb32d215
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:d9445f8bc6541429d03ea16ea1ebfda3d972f4fdf7b8b86d2677161ecc210077
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:4995f4a0a2e5e33f5d1d0f05cdd7bd46a5ec59df977d5a8f25a8c5ac65df6936
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:bd7053275137800b4903299ca23b83898ff9d3f718e4871d1357ca4731f4835e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:cf77c8beac5a1b1c62ec45816adb249cf24857be5151c60e7922313eaeb0f115
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:57bde737e0708ae2bae52360cd40201ccc9caa00e6e7065d1a394f7ba955ac77
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:18a8237848405fe48149f61829fa6268463db9c09cc6c08e14b9588649b5ed40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:14432dadefcb679aa9e3c184de9b7455c20712c30f1b6d8a0cc8814b2dadf958
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:19f23f0cf8d482d72b1af0ed1fe230976b9b20420cbe8d89a74254cfd65b3703
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:894cb993927387be163387e70703fd43c000b0b44a7642c8b2b7300ea6bc079b