Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips-dev, 29-alpine3.24-fips-dev, 29.8-alpine-fips-dev, 29.8-alpine3.24-fips-dev, 29.8.0-alpine-fips-dev, 29.8.0-alpine3.24-fips-dev

Index digest:

sha256:7ffa0bcdc334ebb6afeffd803278ba6ff0132adea1bddc1012f877c378bca35e

Manifest digest:

sha256:ed0258d2436118be8ba8287f80196616eab726d9a7f2df7228e7da768eff5c06

Size

103.64 MB

Last pushed

8 hours ago

Vulnerabilities

1
1
6
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:f3989732551c09326f094fe806ddc3f1d5deae1a82399ee49233ac34f1b79576
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:9ddbc0aa8202ed6e6f1a6ab9dc27ed3d469b728f967652c1419dcdc53f239e30
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:b07359e373befbe1606da940ddb5315849f4ecf9ef5b00f8475895c2b69977cb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:1f472c1bc30f77d0978580ebb789e27f6ecfc1abd3ff21a930a3eb141838bb55
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:375200cbc482e143901ab1af3a13eab746764688cf84ae29184fd82b43a19018
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:9d09759e15e9bc39e7fa1119b7a2c2fe8b8740d9237520e557cffb42e506e41f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:92fd2650cee403f17a6dfa887e8988ab72fee76e56626c631ea20ab75a720686
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:83b838e4d864dfc2e33871af8b360db4b3e77101207441d3b74c8f79c2555cda
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:9ae5cab23c7cc71bcefc328fde6da357f370a8f4c52a63bf9b664aaf12c6c039
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:646a1ad1d413d2b3a8cbe8c73330033d2f56c30313b81b0a0c262bb4782e1c3d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:3e03bba7ecc4e9c59e1235473cefa778bc0329f93133d695a5e5fcd026fc6c66
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:56eb9af569baade60a26dc7512b3aeb61eb3b77fe4e53096962b99eea938e0f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:41117ed83225e0ec86b3339c7fdfdce8de5030226829f0cef9f989cebf26886d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:d16b7aa25ffd7dfbdf088bdafce702fe756f71400d20aa13509a1facc11ab1e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:aed23265ff58806251fedf73ddfaf4d3d74f2fe2c873fd111f91468daf3fc5d0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:7e7af24c4a5f6739816797904710cc2bd000d4973f76d2f5744fd3a4a6b98eae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:e7323ae6f0411cf70661d3789c6f819015ba445964ce37da036868c9d4a7e83e