dhi.io/git
2, 2-debian, 2-debian13, 2.47, 2.47-debian, 2.47-debian13, 2.47.3, 2.47.3-debian, 2.47.3-debian13
sha256:ff83714a97088be2e4af36c33d7242cfc70c228cf51d57558ce8e0cba481ae20
Manifest digest:sha256:fff2cd63ab8fab3af848d9d5b58bb36b3412f703d472fe7be82b9a1cdde6581a
Size
37.59 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/git:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/git:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/git@sha256:44eddbf0009ac1379b9b084a68640c44ca9a0be4bc4a7c9e8a3cc46d4658647c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/git@sha256:bb9fc0137b497442eeb11295858ee3c94efdd5026be2474de0e1422cf9b42d23 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/git@sha256:0d4f6002fee53b5003f64ab790ab2d108d8dd176bbd917e2fef10e1dc741e355 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/git@sha256:ec803e874c1f29c849758685e119f12fc14b64153ee019b414660439fbe103ab |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/git@sha256:c73ab8a4865088d83c22261d62b7acb7f97a206ff0ebfaa5c9dcfa1e10dd83c4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/git@sha256:ba956639db06fa6fd92bb71eff41683c3b2c935862d8ad4bc88886be5fe0fb39 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/git@sha256:3329b54f88fdb08c9a542de3d142293307d3d92f29060e1929d1a0a414c7802b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/git@sha256:ca24f9da3ff0d8289c753ef60aea7a19770f28ecb31c98a6dfcb06a42d39a863 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/git@sha256:6e2adf6cee67c9f5dfc4262f441098d9a20536bcc7ff41933a9836059ad72cca |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/git@sha256:5e23ac10d9c44915d2b50ab39a8972fcccba9e60a8100125233bf5d0d0af65bd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/git@sha256:6317dbff0102456b4c841881bae5c1eba57e8046fe1b2d811d06221c24798885 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/git@sha256:0d7d2666ec7b49a765dd46bc9bf2f2bdf60f76b42d993ec9a8c3193bc9f206a3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/git@sha256:155ec53c2de3a602c5e1aac40de6826a211f3323eacce0ad875ef5f7f9cca2e4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/git@sha256:427d15330b71406b060fb0c0d38bca7cc3eb99c99fe65976f2e0e4e0d8697922 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/git@sha256:101ff62909d4c58dc227bc9d9066d782c359c8417b70cd8f70ba1233e62669a6 |