Sign inSign up
GitHub MCP Server

dhi.io/github-mcp

GitHub MCP Server 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.12, 1.12-debian, 1.12-debian13, 1.12.2, 1.12.2-debian, 1.12.2-debian13

Index digest:

sha256:7c5f310c8d60dc627f033e06c919ed4cfc3cc9fa6c25c1116961eccf653fb414

Manifest digest:

sha256:61d4fb1d71e322ac15e91765939c1a5f35e2be2e74a20dff2bfe0767e1f28882

Size

7.24 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/github-mcp:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/github-mcp:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/github-mcp@sha256:d6a9ae2a522abaeb56341753aefd4bb3650dda9c4925dd0dec543bf410504f09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/github-mcp@sha256:c243211a846e77357da94124e974342dd9a0e12aa9e964832523ee9999287db1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/github-mcp@sha256:c0a7d4d49ea524d408f3a8a13d5340dfdd7f13c0c74e675d33d3d4a724b4eae4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/github-mcp@sha256:c602835d1960f8aee2cf17f22f30801d926c6a6e0dd20ee04a04a54859ff4124
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/github-mcp@sha256:065733ee713e9b1bfcb766175b49f82ac54bbe381c774f7055181e5d97d2e2e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/github-mcp@sha256:f22cfc4797853df94080fbe8ba452c0d36b8d9cd455c59af5bd89ef4fa40e0a4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/github-mcp@sha256:20e27fe06f1248f6f8c55534aaf7a1969af7e04f04ac8b6a39ba0ad778c4860b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/github-mcp@sha256:7f4fd133107a61358caff828176bf89c1ddea69f91ddd26d1dbdd73aa53a0a6a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/github-mcp@sha256:2f809814481483827da7436f4e27b39aa3d9b8709433efecd3f23c37a0bfabd6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/github-mcp@sha256:4102420880abd14baac6fb0698df77124a2c6fe8d026697ee3346662339cc101
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/github-mcp@sha256:faa1f3f0f391499763ea4a1b1681ce3a99130306672801d2db6d404f9b27e109
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/github-mcp@sha256:5b1dbfbb6e81ebbc2df10f96a14f397bb5e4d66643d4e3859b3eb7417013c726
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/github-mcp@sha256:10e20fd55ccb0b82f6334665b2508a79aec385bf1ed630b5fc55e9f80f84f903
SPDX SBOMhttps://spdx.dev/Documentdhi.io/github-mcp@sha256:60a02a7f1649fd65aaa8f2040ce50bfdcb95770cf3c3f3dce6231c8816270418