Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips, 29-alpine3.24-fips, 29.8-alpine-fips, 29.8-alpine3.24-fips, 29.8.0-alpine-fips, 29.8.0-alpine3.24-fips

Index digest:

sha256:bf4961655b0a0b51e3ca1e84c1bd2c38b241bf6ac58a423ea05ac0b71625d698

Manifest digest:

sha256:535e0f3562976a6891b3e64776034d143bb540758d594fa9c1f77fd1322e471c

Size

102.13 MB

Last pushed

9 hours ago

Vulnerabilities

1
1
6
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:bc6106788a23e721d22bf966c6dc33275f4d2b0923b5521f7ee19b26405b347c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:97085ace2182aaa05c879e06a6eb695d0ca21328da8137b5e465bab8e42c8975
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:af7b19bddcd60f21a76e1ce4121a090a2ae1144433efeaf86df0e6229c250263
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:265fa677e9080d2278de214843da1a2a3e17897bdddd4fad5491a3e6f6a35951
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:0bad8e581484756c0fa07a70259282035e8c0dd6f5bed2815ce702261e867b2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:62ff3727772b0326b0dac256a6e6a6bd1ce61ae820c2ff72b8ce4ea9202a21ce
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:f76fe4ef90c9a4af6a5b9630e8d3b4b89a8dd886e06f74049f872a487a0804fe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:572776687691402e1e4669f812e87b78ae374403dbf7d4f277761426d147be44
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:51245538930aad3b0803f3360b0a6cb050b88b92dc3f4bcc4c7ac55c72e42912
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:13075f06bf49eb398fac98968598ada3c898a21ca8714e1d81a19ee3a17ed8ff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:057688a0554b3ec66d11429b2d1d5ee8a529af96dd854c4beaf9151f24cf2e25
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:96a33675e446ed4b7686699d0cd22d81ba38d2cdfd8e2313656c386246b763f7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:744d501ee4496de016ba304c7ff3e9f720e2394886a4c2180e56f1d5e0a2a94f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:4f5f06b25cbd1466894b6dedc4a33041bf94289a30553189c1d34113e6a74d73
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:08a7e7ee67e139f5989f29acc794a2a52882c137e948005ad013757c6938047c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:13ac4b22e37685c409425699648641bf486d05f1641c3c59e6e4f1e9d9f3fa0c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:a9881154796bffd6e477fa61532833eb236953dd983c820c72f0d82ff681c30f