dhi.io/keydb
6-compat, 6-debian-compat, 6-debian13-compat, 6.3-compat, 6.3-debian-compat, 6.3-debian13-compat, 6.3.4-compat, 6.3.4-debian-compat, 6.3.4-debian13-compat
sha256:fffafbbba8d87dc7ce805e806b8df6466c5a94d198f370122761fd751ed7c662
Manifest digest:sha256:34bfad7762aef95c98ae5fa93cb25ae9c5340da6fff3fcb736b2ff18f8f22e46
Size
23.06 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/keydb:6-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/keydb:6-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/keydb@sha256:44ea912d734e60dc94f9635c426c14dd953c8ac6a7825edd58f44acbb473a560 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/keydb@sha256:feaa36b589f598c37be0a92dae237c15723cad9bbf39e5da611b9c5426f9947d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/keydb@sha256:e4b2645db7ffaee40cce67f66ce0644e241ee92ec3962dabda58638d51517d57 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/keydb@sha256:19f26b68ff62c04c5830808daf4259c841f38543a36d1f76d38670d934c027d9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/keydb@sha256:7147ed0edf23db8b398c19bb7e51244f7ba1ca89e660963d82843a7343e275ff |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/keydb@sha256:4c41f447d93b2ccb0befa33ae1f2dd60ebfcd7d70f8ee0d96c4fe84467c80643 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/keydb@sha256:34026ec2ff6d15d0b587a6d8cfa809da3c31b4f420b4a6f7205f34612e5df2c5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/keydb@sha256:bab69eb1d01ea9049ffaff9ba87e19f38b34d78773ab46e2958ebb85754c1bbb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/keydb@sha256:156df99f663af547ca04e5c65acd0a1e088f443108545f8689fc9de031038c6a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/keydb@sha256:3720574c7c0a9ce8e68d01aa2f26f3cd9de1d921bdb35d9240c1c1c2c462d381 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/keydb@sha256:d27e0cb15a5bd66e35c0e5eab011ec3e612b84eb3eff84b69a6f9d5176840eda |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/keydb@sha256:0dd0f809dac7efe5e9d0bd2b70cc5d26fe51f5cce721c13ef805af9a9e2f45b3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/keydb@sha256:ad8eca18ca71a95c194303a5cd5202ee3c503cc1df3a7ab881b5f2db4c91a29d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/keydb@sha256:4406223dd97abd3b2aa0af475589252197ab50d25ad3c74917c7ec1c5e9c147b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/keydb@sha256:f3a7da67fb835a548024402510fb1f0244f5bee351ecf6d77e1df08d1ae7b8bc |