dhi.io/gitea
1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.3-alpine-dev, 1.27.3-alpine3.24-dev
sha256:b5c50192cc4a8a440f49755f36f08a81490de1c398f10b85c940cad819262a05
Manifest digest:sha256:329dd719c5a434ed95a196783fbd2a14720ff9307f0bfc062504ebbb81d78820
Size
88.58 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/gitea:1-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/gitea:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/gitea@sha256:38032f3f587bb5b67adca2fdfca64abfb3eef765bf8e999df1daf286dedb49aa |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/gitea@sha256:9c0155a8cd24c36a0be34cbad0a904372ee99b53e97d8fdb7115699d5fc92f89 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/gitea@sha256:e70bac2f499108a07a0853a7c2e32a21be8fb1b2aaf82f4cb904d491c8d2569f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/gitea@sha256:a0d780ef0122d6d4bd16a6dd82fe7674d7850535db1c58ddca1297b8a01ce189 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/gitea@sha256:a75cab2d321a3a9bbff9023726f4e8da42acd25c1aa6ba5f1c2c3edde8cbdd3b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/gitea@sha256:b5b74cf08dc5cd14a74c47287676592ce98b6c1a1a45302d2050d2673e8c74b1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/gitea@sha256:f49792345640ecf454ad162ff95ffa09fff93dd0396c04a5cf4e4d7616fb0961 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/gitea@sha256:dfd42067e4be0765ca581d79c30d43b62374a0f3aa13dfae61edee51ad75a6a0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/gitea@sha256:fa7251245c84f107a608e21819edd9a272a4003064b343308563a02cb672dcb1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/gitea@sha256:d096e424a71740705279bd7f66216b29d08c7e7627e53681ed4c1fb72a250d6a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/gitea@sha256:aae18b0a23b806e9b4de0703a6d73949cbfcef444af670745b53520438189d5c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/gitea@sha256:31d0062d7071896703b100c6d66318d817ebc2e0ecefd447f9b1989bdfcaf97b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/gitea@sha256:41241782fed9fde27ded53ce5559d56294ab996b192d9daf38fbb06f136d270e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/gitea@sha256:55d5e86be9ada0c0e5585d5e843d411c9518cfe9d6fbedd0e18f3775cd1ac351 |