Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.3-alpine-dev, 1.27.3-alpine3.24-dev

Index digest:

sha256:eaf3685b96d5f98c3fd4ac8eb21479bd7bf407913440f260f15cc97da5919f78

Manifest digest:

sha256:0a323b9bc7f8bf91c0b8dcea33f446ca187832ff94cde7d0e13ac04cf01e9bf4

Size

88.62 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:e1f458ba80d6bf9d729abf21f4402d3f941961b1e5f5567542ac37e13845ab0b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:add75e56eeea239f705731f09151b6c29aa2e7d1209a7e8a9b62354f36fe0eed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:d4846427d597829c4993ccd0f16c03139762d439320765b5f1c8591e5640102c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:8815b4e6769eeae8cdd83643a7f672ca5d9ab9e4b53d3eee023d97fddd6eb2db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:73ddaede1fc99390f48ff10021f676166f05ba0f8dead156d69c47442cb65443
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:d662cf77aff4dcb03b209f1c7ac085feb13a01d774a9efb40f98ca12d60e2ceb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:70b9d4c80e25887538712e0b18d3120b522ac7dc921e1e0095cd3158e602adf9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:03f1b12d30e444c8f7c8ff9db9f3dd57d959ad5ac6b4c334365fd6d1ddefbb2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:c1e7db5ddb8fde86c70f60e026f2bd6c4cd071d1379ad85b90dd2b4bf0fe81d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:380df9d500ce481fe7109c483caa129eead6821460727cb3727f2126f94754fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:a0884e9d2e536ce7db8bae4527b32475e1e72431927b2012c2532331782aabcc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:dded96a94ed53355ed24653178d90344c9688c77a42e60b241216db930cd9a54
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:4b05dd49c3ca7639d2dc6dc2d1dd6d8b70c7363b12dc2dc05059d2d62aacb629
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:d63781ec1f07ad13bb79a27efaa9ac721a65881335ef570521208d67f9e95093
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:5b4d4ac6bedaa859170ed875d1d4d094c6b85958657983e6a4cfda0645b5a8c7