Sign inSign up
Varnish Cache

dhi.io/varnish

Varnish Cache 9.0.x

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.0, 9.0-debian, 9.0-debian13, 9.0.4, 9.0.4-debian, 9.0.4-debian13

Index digest:

sha256:9b1dd49917871522f9e17438b94543be565b6dae3f7a6a5ee78841d83945b97e

Manifest digest:

sha256:7d3f3f4a963615734ff69b25c6d588cd99e2973bb67819a166c442b5fca09394

Size

72.49 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/varnish:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/varnish:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/varnish@sha256:73bbd9cb92e18d1fb5f2cd6a1e05ce9868690dd22d9cc069874b281dbc548d45
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/varnish@sha256:c89d8af15d65d68ab2195041dde4a3c279d5f76dd76fe49da820fb94871cb67f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/varnish@sha256:55495a7204f5b5b705ea8b3f88ea87fb67cab4b4ad10b7023146193ed86f2f13
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/varnish@sha256:36c1ef1b4f1e51bb5180603e6157070c32922258b685e3d86abe62d4d379ed2d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/varnish@sha256:1d5e89b1a0fe038715d749b3856392481a3387d78961e070dc3693a9ae4bb274
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/varnish@sha256:1e81e1b5b850e79624fe02986a6ab5dbc3cbef3f44b03d905d91ea3b97fa412f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/varnish@sha256:9b03f040a564bfb92499b10b6390ad119e9389fcbe83c4563c52bdc5043ed035
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/varnish@sha256:9cc9a35dbfa91a3af7bbd197d1d053be8df6db429bcbede170643911882a5b47
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/varnish@sha256:91a095df5c715f682831e0fdcf47710f63716cc275f5dd26d3efd844e93106b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/varnish@sha256:c86b6dcc01bee30611fcb7a4e207b79a4cd11fa10811e878910011b4d6a3a7ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/varnish@sha256:da72b7ca6f6e7453ef252ff432c250209e064cba30df5ee43a4c0f075e3c1f24
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/varnish@sha256:e6ab9b39331a1e786866ff80cd1dbf080e6bc738bcde13e787bfb507c4e66685
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/varnish@sha256:bcd127c705395794a457bff2bfbc0b4e59a7ce032a9944e3e18f0a38743766d6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/varnish@sha256:f60202f7506e8b805f570229c42542609b9d37215cccc55484eebe301057bbf8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/varnish@sha256:3d92286e1122e93408c5bd8fd14d090e7b653f9bcb250704939f1a552f72d90a