Sign inSign up
Gitea

dhi.io/gitea

Gitea 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.3-debian-fips-dev, 1.27.3-debian13-fips-dev, 1.27.3-fips-dev

Index digest:

sha256:28dd0f204a7d893a93c5597fb2a65714f756b226480f76492f33392a28b1169b

Manifest digest:

sha256:112a65d17142ab689097527a77cd51f9543d00929fc4c3275cdbd0d278aee27e

Size

119.66 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gitea:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gitea:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gitea@sha256:abce2bb899d2e7b03076638add66ee95e87eec79e36b65d859b2a2cbf02738d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gitea@sha256:9d6822f62107fbf38bff1446afaaa95dc1b0306da6268af7d966acb593489bc5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/gitea@sha256:95daf0bd050da5ba30a89f5ae93571976585a301a3b8eb6ba527169b36b0ca92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gitea@sha256:326018332e86e90f3883ef82bda8fe64afe47a12d20f81190f228c4bcde42915
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/gitea@sha256:4cfb69267af7b558d224d932b0d5b93e9fd97dbba64d186593b6578e295c6fcb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gitea@sha256:29e0eebe229e5280ab529d67e38e658e7b3fdd2b65c23331e7ff5b408def2e95
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gitea@sha256:1c9b7f257de74838a6dd1011947bbf57efa88ed49f7137ae302e213562ac3228
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gitea@sha256:3461452862dba8c56f4672520ef429e24c482fecd3807f745f7c7f9d24376642
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gitea@sha256:cf61c05f779ea31238a6317c71b5f57c5f14f5e55ecc1f72d44f6bf13f273d1e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gitea@sha256:b8d11c1c4ade853e5125e6ce8f5882c7891d640d2d9ff5f5965c9060c5091ce6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gitea@sha256:c43d97191bee94e374484c01468e47d7488c3ac6ec52a3887333115869cc06a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gitea@sha256:2d8aa69a1d767609fae6c373c80c395a15a6836f14b4aa084d6f74218e6ffe81
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gitea@sha256:8ff08b67d060268819e9c8c213c39c6c3539df22fb18556394f5cb9b699e76dc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gitea@sha256:92060bf0686521a505dc50ff063df25e9b004ded260d62aa4987b0de647acfca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gitea@sha256:642a1a8d22dfd9e4d91bc486c5c81bf421e6bb25a5a78842767cbccfd668f362
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gitea@sha256:12951f9a02e36cdae062780109b20044ad1eac6b315a81c161f9d234460602f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gitea@sha256:6ef64610eac7b90a4cd207e3b1b8283758a0b611448d241a864bc78cd0b2dbaf