Sign inSign up
Git

dhi.io/git

Git 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.55-alpine-fips-dev, 2.55-alpine3.24-fips-dev, 2.55.0-alpine-fips-dev, 2.55.0-alpine3.24-fips-dev

Index digest:

sha256:0ea22219fbdbdb3d1836303b574d20fa2d07041dbe447a72372ac33fb6603019

Manifest digest:

sha256:a9d517a68ca5d144eab22f552ff465100730240b6e6ebb9f31728afd62f0fff0

Size

16.00 MB

Last pushed

18 hours ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git@sha256:acfb6bf57b0babd7459908d599a8702350fd5b472b678f8702a0ad9cf83f74e3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git@sha256:05d7fc5609c402a62ae5ef64646267458c620e1a0277538c599d1c3f43280e7b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git@sha256:feb7e6d08e5d16e586826bdbab31dfc4d8d5ede62f1e24195d545a12dbd6937d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git@sha256:1f60e2427861c422969218a670c93a84c3746c33368313becc543409f715911d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git@sha256:1bcda62a99f41126bd613985a61be7535cf65ca977ccd003ce5ca49a8a8ecf9d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git@sha256:33b806bdee475c00412e82355811ac3939a549fcfe3d983b257df1951e2f370f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git@sha256:0ecb0f16af0e7ce7c2677e9e760fcd529c26de66b3033d6413d1d71f07d34e63
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git@sha256:6a941f15e17d0543a2c5fed733b3fab90c8a66ae34253d10454893381c70f1d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git@sha256:5b5a771fef4267ee995104dae25d96ef2c91ba1a128490dd3d0be12be03927ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git@sha256:df359f88b92c201f3d1c27508ceaf0bc1186fc66cdee48ad5a2bbbd6e1ab4466
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git@sha256:ac9c89f64c38d5a88f51508e0f2c13458d7113867442cd05a5c400b3a309ff0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git@sha256:92dc7a0c2714dc224da1e1ff63565845ff015972f84b6c2d90309cfe94dd9913
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git@sha256:8ea0767a7f66a38d38d80a61a091a0143816170d7ff8a4009b76453ce50e0015
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git@sha256:8fdd6bb693f8adeed9a7959e793d2df42a626296dcc5f09baaafbaf24ffa6b9f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git@sha256:bea6ef0fa476d5ceaec008bf52428139a8cbb87a7bc67909d4835e33463f4689
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git@sha256:7db9194e3a09bf2fae0717ceccc6f82546c017cc13846999324c6e83453a787e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git@sha256:ded2c0683ca01d6d704143cbdbf2b6f2ad2dda343919e48111fcc7b751f341b0