Sign inSign up
Docker dind

dhi.io/docker-dind

Docker Engine (dind) 29.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

29-alpine-fips, 29-alpine3.24-fips, 29.8-alpine-fips, 29.8-alpine3.24-fips, 29.8.1-alpine-fips, 29.8.1-alpine3.24-fips

Index digest:

sha256:adb1cb907bb7d1e4e35b9bb850b995c16264e57395f4c879f640021793ad6a44

Manifest digest:

sha256:e99a3e64e27c53e981845140a84b0054a08475986eaa011a9c34ea52ee0278d0

Size

102.13 MB

Last pushed

4 hours ago

Vulnerabilities

1
1
7
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker-dind:29-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker-dind:29-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker-dind@sha256:7dc252e68ce999067e2c29efb1b1943cea69980c050af9c1c09fd7860d4e3121
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker-dind@sha256:50ea40b166d575d594478cae60b999088732290f67c7024e8c6a6215b83fd6c9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker-dind@sha256:9acfa1d0449410ed19628290512a0f7e491feb9d2a4fb626c71189fc64bc7910
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker-dind@sha256:c4ce40a64e5ad0e996ee5c017eba68c55aa5fee45271117d6ad6dc905a4e1356
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker-dind@sha256:282cdcf0912db8364a1078645212c272509e721a568d98ba551b2fbc7e4a5b27
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker-dind@sha256:7055a3eed1db36597c398a298e0639af8d8e775398fce07339078f75cf0fc794
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker-dind@sha256:2b6f213d9ab58ace4a6c2136e3c880c75b0fda2523071c088c63e51ef4c1b42d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker-dind@sha256:58a79b065810e082450429f20b48bac07647a698cd758c817d4b54ca936515f1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker-dind@sha256:2b8aae8f79a88533b3649c2da27e4a38b5ee1926fd268f692b0eff9baf46d67e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker-dind@sha256:3cf236ae13b685ef9aec7a8e48c6340f50a69c888ffd6aff83e4debf2134a4b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker-dind@sha256:7e4d1d1caba98e2d11dd66252e92d9895017e945c4d71b925b5f6d0ecc1b1408
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker-dind@sha256:b491a56f1ed2caef88a90734e5d9ea38c000adfb3835042c5509733876e7221d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker-dind@sha256:386ccbbdc4d81f542a0ae8da742ab0289d4f326a5f32b47e96d6f576eace87b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker-dind@sha256:86dbc2ac34373c0d5c6264d7bd7f57649b126c2f3eef1e340734cdf10fb9f781
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker-dind@sha256:3e579f986a3ed3ed113c07ea97e013222d662d8a8059b7c9f6aae657cc331cbb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker-dind@sha256:024922a8ac8185be6f564760804456e4b8a198a8a55fa3ba69b7ebb8c157f298
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker-dind@sha256:2384cae766afabdfeab00b7b5d808cbfd2b18f45b0f44ab07a6ebe1953d398a8