Sign inSign up
Git

dhi.io/git

Git 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.47, 2.47-debian, 2.47-debian13, 2.47.3, 2.47.3-debian, 2.47.3-debian13

Index digest:

sha256:ff83714a97088be2e4af36c33d7242cfc70c228cf51d57558ce8e0cba481ae20

Manifest digest:

sha256:fff2cd63ab8fab3af848d9d5b58bb36b3412f703d472fe7be82b9a1cdde6581a

Size

37.59 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:44eddbf0009ac1379b9b084a68640c44ca9a0be4bc4a7c9e8a3cc46d4658647c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:bb9fc0137b497442eeb11295858ee3c94efdd5026be2474de0e1422cf9b42d23
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:0d4f6002fee53b5003f64ab790ab2d108d8dd176bbd917e2fef10e1dc741e355
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:ec803e874c1f29c849758685e119f12fc14b64153ee019b414660439fbe103ab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:c73ab8a4865088d83c22261d62b7acb7f97a206ff0ebfaa5c9dcfa1e10dd83c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:ba956639db06fa6fd92bb71eff41683c3b2c935862d8ad4bc88886be5fe0fb39
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:3329b54f88fdb08c9a542de3d142293307d3d92f29060e1929d1a0a414c7802b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:ca24f9da3ff0d8289c753ef60aea7a19770f28ecb31c98a6dfcb06a42d39a863
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:6e2adf6cee67c9f5dfc4262f441098d9a20536bcc7ff41933a9836059ad72cca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:5e23ac10d9c44915d2b50ab39a8972fcccba9e60a8100125233bf5d0d0af65bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:6317dbff0102456b4c841881bae5c1eba57e8046fe1b2d811d06221c24798885
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:0d7d2666ec7b49a765dd46bc9bf2f2bdf60f76b42d993ec9a8c3193bc9f206a3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:155ec53c2de3a602c5e1aac40de6826a211f3323eacce0ad875ef5f7f9cca2e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:427d15330b71406b060fb0c0d38bca7cc3eb99c99fe65976f2e0e4e0d8697922
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:101ff62909d4c58dc227bc9d9066d782c359c8417b70cd8f70ba1233e62669a6