Sign inSign up
Valkey Bundle

dhi.io/valkey-bundle

Valkey Bundle 9.1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

9-alpine-fips, 9-alpine3.24-fips, 9.1-alpine-fips, 9.1-alpine3.24-fips, 9.1.2-alpine-fips, 9.1.2-alpine3.24-fips

Index digest:

sha256:0bfa91b7e070c1f748fc4db82d1fcd3ed58655f7ca31cbf487abf7c857c9e8a6

Manifest digest:

sha256:7c1e51f114b8bf04a1e1c6ee253458d28e2cab6aa80a08f30a2a000acc37cbe2

Size

59.60 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/valkey-bundle:9-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/valkey-bundle:9-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/valkey-bundle@sha256:7f879bdbe64c3b58b9695ca1e54d59f1a412f618a8d5e49737f9d88025aad928
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/valkey-bundle@sha256:0ef941eb0e909b5a66dbc42e1a81a455ef46a6f19e439e75dae78d7cc2e50f2f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/valkey-bundle@sha256:31e568b07a67ab3542c05fd883c7f8b7b73016c4add05c079bcbea7cf48ae407
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/valkey-bundle@sha256:dea4af0c6006cdc496a352acac56a5f919c9f2c7c2989d51f5a78b1f4ef77b9d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/valkey-bundle@sha256:3d5b85eab0e262e4f490d6fe367a06336d1ed250b38cd7ffdf768f9c3274a5e3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/valkey-bundle@sha256:69db268bbf0c40454f12d6b299995233ab6ca1d7eeba33bf0c459e02e461933d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/valkey-bundle@sha256:27a311f4642e0a6f2aabc9ec50bae26ece63bf0b2a631a462bbd6b5a2105655d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/valkey-bundle@sha256:c936be1f3bf966346122d417d23cf74a8dc760ea41b18c057f83d69ba7919f5d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/valkey-bundle@sha256:0ea558e9314e8e1730e434679f967193c2c98cca84d47cadf9e5d3f03ed22e03
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/valkey-bundle@sha256:16c5b3794fbdfddecc88837a48113e3a5241ec9e7a3f94edbd6f0e5449ff07f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/valkey-bundle@sha256:58e169b43f3a50dccc52d9513425a197c6283d551f9fff44440fb09e1db4935d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/valkey-bundle@sha256:34641d64df631ab2e88387b3308ec861e6e6abd405954396deb585bf951e8e71
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/valkey-bundle@sha256:8090f1b1ef15b2f06224f1c33c111b30573e78bab30dfdd1a822e59e65289efa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/valkey-bundle@sha256:09b5179716f09e2ee436fa87d4539dd89ad99626387e13072f0cd003055de880
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/valkey-bundle@sha256:8e3fc265a51cbbc40c79d4bf1507ef35b33f2eb804e2e4d1f697e65ed2872cd3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/valkey-bundle@sha256:a62cac327b081c0bba43518c0521b5d1cdfb63bfa213f561fdd035bf26386813