Sign inSign up
KeyDB

dhi.io/keydb

KeyDB 6.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

6-debian-dev, 6-debian13-dev, 6-dev, 6.3-debian-dev, 6.3-debian13-dev, 6.3-dev, 6.3.4-debian-dev, 6.3.4-debian13-dev, 6.3.4-dev

Index digest:

sha256:76c7205a4d515be01171038abbdad3f15b0526bc80a74adc0a041d3c514ca270

Manifest digest:

sha256:b6dfb6f930546f6099d6898f6a9f6ff747f8417f9770b7cf1047b0beaa17dd1b

Size

32.35 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keydb:6-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keydb:6-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keydb@sha256:16e85f97419335a6ad37e5f3e4be16832247a965813786b1fa45dff1d47dc5c9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keydb@sha256:60d8557145e56889f7f949e843a7341ac791e2f1bb23205bba8affca2f91be9e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keydb@sha256:8cf767b962ee4099fa1f04a26a508012ffc53060d94cad788d82726e7c0256cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keydb@sha256:507914fdc14c49a94f6e66da3ad452089d9a9a491eb5e319bf381b7e39f97712
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keydb@sha256:f129e81731424d52aebb9d4e52a48f088b241e6700924c1a9bdf27be4696de8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keydb@sha256:99c88472aa6a62d16f76d62856e74256c6e8c240ee1ae7802c8cb27e22b352d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keydb@sha256:75f057361f06859de94de41b41df729f77dce3fc44b5cf62f0bbd5d3992e5f8c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keydb@sha256:e33213b91cc8602867e190d99c6c4cd72302abfaf745fc8e95c35710e1eea82e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keydb@sha256:50920989bc8a3af1507d86e9c538b0c9e12c68ef1908152ae93396dadc49b3ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keydb@sha256:a9a615d4388bbaa9773e9a2fb694bf7c63461f6050dabcfa1db7e7e9cf1bc972
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keydb@sha256:c5a6e927b5181af3d1f1f505973dd66a5313540ab26e928a85912cda50de4462
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keydb@sha256:900e9c8e35f685a6a7dc51b60242d96e5e6ab037456fa42643d2dbfda8de5a48
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keydb@sha256:b5a8afc57b407acebc8918b95d1ae389a8bb30177a0d39d324b724af269ba9da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keydb@sha256:0eee9bb561f190d531e3be591b0f53517f2c6f13954362ee80f7c115f0f8997b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keydb@sha256:44e734d3f764d0cf490e4f87901e9a41e417e835ff08d1b87f4dde126ee675c3