Sign inSign up
Git-sync

dhi.io/git-sync

git-sync 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.7-debian-fips-dev, 4.7-debian13-fips-dev, 4.7-fips-dev, 4.7.1-debian-fips-dev, 4.7.1-debian13-fips-dev, 4.7.1-fips-dev

Index digest:

sha256:1e6d91d0ad26ce1d405310a092bef03616a791c2133c76dae7e60df2e91a5017

Manifest digest:

sha256:2106e850e47ac64b527e82ca87b4d6b70b60b3d3d98bbd119e1d72896392a686

Size

55.33 MB

Last pushed

22 hours ago

Vulnerabilities

0
1
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/git-sync:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/git-sync:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/git-sync@sha256:42c65b100fa203c7e8ac9bdf5a802e611620ad111f3e7165d21d9cfa12da2989
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/git-sync@sha256:ffe2673389cdc9ab0fbf901ebb789f8917b6578932e9bbfb6c46deb8b857d43f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/git-sync@sha256:fec0d2f9ff1839f71cc313078adf05ce6fba95cfd83d0708f0df4e64b6f06c8b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/git-sync@sha256:fd6df53cbaf0ad9591bb831bbd9a19a02784970e6ba975b9d6c023bfa0d14c02
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/git-sync@sha256:00847b4fd749f526143f5ea4d43321cfc7fca1dfb12be17ae8893b740c4ed2f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/git-sync@sha256:ba56253e250dd0dddec0eba70b090f25b321c044ee4b8bee970caf358b525f8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/git-sync@sha256:fee93a1ac321aae3a9d2a417b58be0b375ad72d4581c0983fb4a5ef41d905d7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/git-sync@sha256:e14e9b61cd26a08f06b124ab9c1c1538b12ac9c8eafae60b7400d0bddfeeef0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/git-sync@sha256:730c73d04cec3c37a4ae6b24fdd512892e147b67d533d3b4c74f99bc9343a37f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/git-sync@sha256:d6df23a38f3059abc6fc9ac54494d22e0600b7b6f0ae56bb09c103c3718ae545
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/git-sync@sha256:6a7d6bf0d15528ec87b34684c8c8542bd7a758ffcbe484eddd80923c2d2aa302
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/git-sync@sha256:70acd83297752b83768f0db4e8b44d27d7114a928decc025e165a7c6d090a0e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/git-sync@sha256:b85773bb604651a1e68dd66c34df3cfed866382c2428bbf04e4e1e9ae7cae27b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/git-sync@sha256:1b8fb22d254f59215c7944a80a293ccc05f5cb7d2c51e94a0bd6b915532f49d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/git-sync@sha256:a6616aa56dbd128df0739d05dfe23c88b0586289a4f59085e59da9107edebeb6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/git-sync@sha256:7cb7e8ffa64fdd841cff67d56e22be43fb5bfbf37735099c5f026a17082e145a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/git-sync@sha256:348cafbd7dbda98fcc205470250369416de6530253a8013381e4beb03b0b4aec