Sign inSign up
Varnish Cache

dhi.io/varnish

Varnish Cache 9.0.x

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.0, 9.0-debian, 9.0-debian13, 9.0.3, 9.0.3-debian, 9.0.3-debian13

Index digest:

sha256:33411a438ded4457722ae264cc65cb97fc5277b35b7dad22d3c81bf4468eba53

Manifest digest:

sha256:8a028183c2689dd12807546006f1b0a2306fdb6f61d8a4589b35c23a334339f1

Size

72.48 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Mar 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/varnish:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/varnish:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/varnish@sha256:c14afb822fa1e3d5f79f2a000c3753c9a9b5cafc3f73a13f37eac1ee3f7eaa57
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/varnish@sha256:bdc5c48c2c89a1a3db33dcf512fcbfd79a27ca914dacf5c15ca3924ad24bbc2e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/varnish@sha256:7005391a24bb3e455b611a04efa72ba735efff77f7339d7da6fc6ac884743e41
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/varnish@sha256:5ddd074b6ef98e00ce9b24e7592bbbd7ada981d3024904afb96d5caab6bfadbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/varnish@sha256:810dfa75db5e379458cf14eacf86fe3ebc4ec77d8513f4702dbabc9ad38dd3a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/varnish@sha256:945d252743924b526e328038bfd7d30fd76ad7008575a3fd33a8049433e95f01
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/varnish@sha256:d78074b06d0a6a87a410c88b749e6a344c828bc20f2ca59e1307c06e6eb04eb2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/varnish@sha256:36727f4b5a766c859bc7a0dce11e672966c0455880d546b64d6015dd2a0023b9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/varnish@sha256:89e6a53725532d722cae9d682b1f9057265127e3c1e29b4e3a5ca0ab3efd86af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/varnish@sha256:d56fdb7ec3e945fc7bc4fce2adf28bae30831524c9a65a549f9f2315a7f773b7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/varnish@sha256:c961226d2fd53e22517255f4fe8ded23274ef17e83ab0430e31fd11149ef226e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/varnish@sha256:a39c3bd6c8c874f19e8e611cc415bbf1925a0e054561fa2386ab10299dcc3b7a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/varnish@sha256:ca56698a666a965700fcc96d7ae68959c9ae1e05bebaf9d4eabfbba807e32e7b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/varnish@sha256:3ceb5a7a4e6d750f71952985c84b60b3a31f0e3805cd303d2e86ea5d1880c3f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/varnish@sha256:7c9cf4033fc8ecfa12e38dc455909cea7f279e3d440ea334cf85568189f5adb9