Sign inSign up
Git MCP Server

dhi.io/git-mcp

Git MCP Server 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.8, 2026.8-debian, 2026.8-debian13, 2026.8.31, 2026.8.31-debian, 2026.8.31-debian13, latest

Index digest:

sha256:0b5a90db8637ce39f8dbb38d2f639a5fbf106a57b8272d2388d9083152a2440a

Manifest digest:

sha256:748d6a4b9fd2b226a8572fa9d90c79096e1b51207f347dfc9c87b0cf6766ab35

Size

48.05 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-mcp:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-mcp:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-mcp@sha256:33f82fe3aeecb952ab402d9bc9aacbdfc33f590de18fc3a41c630c4bd7dc4d0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-mcp@sha256:805048e4f3c3a65b353215556a241bf4779a7dc389a3ba9ccf74c6d17b89f60a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-mcp@sha256:59a8cba565c8f4b282c417d73ddc8ff9463fa7b247fa9587e867250de6a1840f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-mcp@sha256:c1d8719f3106dfb0c9845c065b33424ccd421f342b28abc68e246b80e0ecd5cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-mcp@sha256:0a7a12fd4ba81badd198ce1eb86023200493a36cbe869ffb7ca07bf98b956007
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-mcp@sha256:f0ad1127ae4a640d79e7a5a5b13c76f4a4f3c7718dde3b82bc7f5fab02d55814
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-mcp@sha256:e6fa4cde5395a888350245898e88c9c0a432196307a94a2c4b277c6838e75859
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-mcp@sha256:8f11cca5782856718591f9ed1c03a427cef7e44cad91ec444597e2afad89eacd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-mcp@sha256:3f667615a1a70eeb795abb3ee23bece74997cf580e9d8909e08662ce54529392
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-mcp@sha256:6fea1a6081f0b5f85f56921b343c2cad622d730194bd5263a2cda059657d2076
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-mcp@sha256:27dc092f6b1f3cc3974315e70fc5ec99d5e37dde83cbd9367df7413a5797a94d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-mcp@sha256:bce1505c30b0bb22e24bd42d496edc038af5b90cb06f70bfcfb85d19faf68740
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-mcp@sha256:77382e13214536ebc8cec323865ace8446caf546e628db0f60a29f9bba2ea568
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-mcp@sha256:2b60ff95d68a1e10514dcd6c2276310b0d0c104ab2fd3642417b4e958564bf07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-mcp@sha256:1e8e17033e8f7685b0b9153d9126fa4881f417e419195c2ac26479427529d658