dhi.io/github-mcp
1, 1-debian, 1-debian13, 1.12, 1.12-debian, 1.12-debian13, 1.12.2, 1.12.2-debian, 1.12.2-debian13
sha256:7c5f310c8d60dc627f033e06c919ed4cfc3cc9fa6c25c1116961eccf653fb414
Manifest digest:sha256:61d4fb1d71e322ac15e91765939c1a5f35e2be2e74a20dff2bfe0767e1f28882
Size
7.24 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/github-mcp:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/github-mcp:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/github-mcp@sha256:d6a9ae2a522abaeb56341753aefd4bb3650dda9c4925dd0dec543bf410504f09 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/github-mcp@sha256:c243211a846e77357da94124e974342dd9a0e12aa9e964832523ee9999287db1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/github-mcp@sha256:c0a7d4d49ea524d408f3a8a13d5340dfdd7f13c0c74e675d33d3d4a724b4eae4 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/github-mcp@sha256:c602835d1960f8aee2cf17f22f30801d926c6a6e0dd20ee04a04a54859ff4124 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/github-mcp@sha256:065733ee713e9b1bfcb766175b49f82ac54bbe381c774f7055181e5d97d2e2e9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/github-mcp@sha256:f22cfc4797853df94080fbe8ba452c0d36b8d9cd455c59af5bd89ef4fa40e0a4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/github-mcp@sha256:20e27fe06f1248f6f8c55534aaf7a1969af7e04f04ac8b6a39ba0ad778c4860b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/github-mcp@sha256:7f4fd133107a61358caff828176bf89c1ddea69f91ddd26d1dbdd73aa53a0a6a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/github-mcp@sha256:2f809814481483827da7436f4e27b39aa3d9b8709433efecd3f23c37a0bfabd6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/github-mcp@sha256:4102420880abd14baac6fb0698df77124a2c6fe8d026697ee3346662339cc101 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/github-mcp@sha256:faa1f3f0f391499763ea4a1b1681ce3a99130306672801d2db6d404f9b27e109 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/github-mcp@sha256:5b1dbfbb6e81ebbc2df10f96a14f397bb5e4d66643d4e3859b3eb7417013c726 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/github-mcp@sha256:10e20fd55ccb0b82f6334665b2508a79aec385bf1ed630b5fc55e9f80f84f903 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/github-mcp@sha256:60a02a7f1649fd65aaa8f2040ce50bfdcb95770cf3c3f3dce6231c8816270418 |