Sign inSign up
Git

dhi.io/git

Git 2.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

2-alpine3.23-fips, 2.55-alpine3.23-fips, 2.55.0-alpine3.23-fips

Index digest:

sha256:2e81427d7e0891c7e382c4d24563cee1349e5bbe4ea4e5345db83add095ecb00

Manifest digest:

sha256:c4ac2e843864e92bd001190503a0cb89c20e1042b49de80f4b8b7dfab617940c

Size

13.86 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:faa3424ad5500dfe026ad601e11d47fc457447f9be7635bc9554267319d1682c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:af16db0b7d5a866c88fca1e9976417ddab85a2347b23a378acaa90836bb3551b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:6f6cde8faaea8642831057a3b4a9031f78971f789fd9f04ec8b257bcdbaa5bf6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:378a8f2a904985a2c6bf8574c462b739e0ef6a914502a328eff57016429be5dd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:494b8bcc36fc8d36b22aaab5b7902d9e4f31e2c18ffe76827b28dfa59b6d1e13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:ff1a2553d0ecb2263f3b33436359882203b17b66fb3747b7cf4a6c6d58d72e14
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:7990b948cb2fd90ff898490d2fda8e128fdd44622aa56451cde50d275889392d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:c5863d9c543529ccf7aef67705baa73fba855dca8d41db49f9301a7bd66e0175
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:6f9a5fd44d1ee83a83234abb5e8e4c0095669004eeb4046ae23c666aacaacd0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:ede784605facc2cb7d836d4cded700cb1fcd30368eca7ffca655b051b6a678f9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:d7f0d643f54a4651d38de37a253a467e073e7eee50a99de12b1b34d5fc9aac02
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:d56de0d9c01bfff4b2e90b247abe1e528b5e4704939b60137a4627d8548a1389
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:488d0138bdb9fed82331c0a98d5171a551406acb5468c7fbcdd22836483961ca
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:a7188a73c2b7aa8ec8686fb856fb763e076da0b21a57f939e91877b3a465cecc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:18bf86758fb889a1c3dcbfd71c96e7c61bb936e367bfa6dc8749b5af2c30b344
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:1ec33780c9cb15faf057e6f5be74d2847c2598c0e3e5c6d14c5b698a8e1bfe02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:4ea6167248197e6fe9c980a37681023668bf54855002ebf62ea8efd6e32467c1