Sign inSign up
Valkey Bundle

dhi.io/valkey-bundle

Valkey Bundle 9.1.x

CIS
linux/amd64
alpine 3.24
Tags:

9-alpine, 9-alpine3.24, 9.1-alpine, 9.1-alpine3.24, 9.1.2-alpine, 9.1.2-alpine3.24

Index digest:

sha256:3adc174c2c2a2889db9cbe84cabff66294f033f41144e224b49e88a2e264282f

Manifest digest:

sha256:586fdfb07cffdcf7e25cd304474eeeb5fa2f836b85057dc895c8ccc5e18dcac1

Size

58.56 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/valkey-bundle:9-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/valkey-bundle:9-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/valkey-bundle@sha256:f5a23a8a95c0e0cdc6d06fb7b01c68a17beb58d31ac9ea4eb8fb886418e2313e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/valkey-bundle@sha256:1ada9e91f7758ce18672793472bb1c82ce58dccb90e6a84007379b729a917e5e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/valkey-bundle@sha256:a91abe47e5ec5144b06285435eecdc70441e86bca37550fc712d92e00cb8f22c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/valkey-bundle@sha256:75b5d8f4c2c0bbe01b5a99613fac90b46d73330fd62772f2bee14932e08f7cbe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/valkey-bundle@sha256:06727c213c44343aed3d87fa6f0f5e6bbc8431a1fc55180290ce410a90e245b4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/valkey-bundle@sha256:4455d1698885041e2314d22ba64bd3c5c7fdf75cf2570c4c4b70c0a333144e86
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/valkey-bundle@sha256:d9a6e89034c0e6b5c5c5a37e77557524545f10b39587155c337e1e96dc3904de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/valkey-bundle@sha256:43d657f976234f9b39f42313af2632acc6f1414228d85ecfb870b5f69493d28b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/valkey-bundle@sha256:9d7eee2f75c2d7d177cddd7470730af497c9b6462ee8d3f7dbcb20aca66f56ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/valkey-bundle@sha256:3462b8886d4e6a6b2a729f7e9a85031e58338955f2b328093bf7178a102479a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/valkey-bundle@sha256:35c0575f35e459f6f07d88c4ea586314ed3254c9966d2d8971bcaab172e4cf3a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/valkey-bundle@sha256:8764c4cd7df3786d017021f68976dabfc7e3e87d5415ea50868125ae9864865f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/valkey-bundle@sha256:ede5fa248cddc9a2361edcd908a11bdf71a2cf01f5a6efcc7fc799825ad4db30
SPDX SBOMhttps://spdx.dev/Documentdhi.io/valkey-bundle@sha256:3e89cf5a236f996e55f41362cc4930ddcf6d83220d8435687a708e003e3c7437