Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips, 29-alpine3.24-fips, 29.8-alpine-fips, 29.8-alpine3.24-fips, 29.8.0-alpine-fips, 29.8.0-alpine3.24-fips

Index digest:

sha256:c9ed905414d17b18b5b0f7efcefcc849dceda29eb6375e6c92bd4f9068918960

Manifest digest:

sha256:aadd1f38f82651f49c282ba37ff7202fe6bcf7b27caf69f21d4e9e75aead72a7

Size

102.13 MB

Last pushed

11 hours ago

Vulnerabilities

1
1
6
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:7058397d91c50f0617c2b5c7cd15ac1f9210ac1344e8c9648fa4b995213b2c5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:85c672d72db080d1ba294a602d1e7d93d466fa6184a5f19d8919864c702e677e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:b3f0402f8f626dd8e1bad0543830b7c9d2f1052a813ff0a5f777ad06d9701aec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:8da77814d3151c219cee52f5676be49c830a91c5feff75553b26b7ae7b3d2e58
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:49fd686d795188a4c92d62b1a3ac651fe0857c2811a92598d9ef736628109d1a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:2cd125d51b84814300e3e2a90b072d11792dc780650f0092b03c8cdf4352c6dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:d4424cee2b8d5a4d65cddb80916543d16a2999bedfe72afcab5e8dcb9e6e193c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:cb4ff5aac3f540c70105b480671a403c80e1dfa1bd98a39830892108d1250ad1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:fdc4907217df21aeed838758173076139028cb03fcb466206a6b1ecc5d351b32
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:232b487661dfc4c39f937e13c8d9cbf1de30b24fa6f00f138546550b85b8064a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:fac3f69827a1084c280bc23ddd2ae413aab852f7dc8d271780ff1e8debdba2cf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:7256e31c3ba6542bcc73c2c554f5d07e6dba0f86dfd71a278e1d66af9ebe7cf0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:e3463df0af3df86cda99c8eed4932adb10768dbe66b291db87b8c092c0633321
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:ac0a148e4710f2ad0c6de35a1e2094b57dd6f07d3e37f18d6e4bc26e76feb5d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:5f1bbe6bfc46e49c75d5409292f67a1c0613bad1e94fb1f0a3b79999d9c731a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:e49e23d9b3f45b3ac2efbb598abe497d7bcfbe3b9686641363a8ea2e62e96cf4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:9020c589c4e29ce2ff935af8ce369867a88959b5ca5bdbb2a1df16f08545ba79