dhi.io/keydb
6, 6-debian, 6-debian13, 6.3, 6.3-debian, 6.3-debian13, 6.3.4, 6.3.4-debian, 6.3.4-debian13
sha256:742b52382cc4c8463026350d3e75d9337b53def6c77e8365fee082280e24ddc1
Manifest digest:sha256:c5ca40704953a7abbc07f2b20449110b07f275ad9852590540ef69297efcf844
Size
17.95 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/keydb:62. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/keydb:6 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/keydb@sha256:a9e5b5bb99350f34e4ff200f16f9210da208f532b8061f83fafffa2f96138507 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/keydb@sha256:f1a0f984b2603717f85e6731f11e69247c5322066d80e7cdd15c81da2fdcc98c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/keydb@sha256:3e2ed691b6ec6e3f5b336fc9bfd9fd64ebce05e0e17fa0efe27a9905c154c6e9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/keydb@sha256:dc7a849679a91d54fad73e9b58b4a5b86f3749dcfe101b0eadba43dd52e119c2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/keydb@sha256:b6ec8cce21aef9cc8a766dd4e3d5aec97ecd00b1f9607336b2f45cb4f971b714 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/keydb@sha256:593af1acdde62864ad0f5bdd00f47ff77a6a5b326bcf3b9101cc4a2a9190d3f0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/keydb@sha256:b2347297dbcbb5fc909c2cf7f54dfd3f66787dd79e8ffde024ea3ada5af85aa7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/keydb@sha256:089c4d57aedf17ec1ba39cf7c14075b41d4b24bfe1ee363d379efc64a8378dcd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/keydb@sha256:e9517af0536666006a7d78cfa3ff75a99959d473d374f49bf84669c5362edc90 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/keydb@sha256:68a5c900179fa848c6750e007eab86d0af006a925098f8667ed2cefb30a1dd5b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/keydb@sha256:67c69b500776289521b73cefc48a60c39a810ec50db6de9550d96eb117837a85 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/keydb@sha256:036d33f58ece40c6c7a706de87e05a5b0388f53a3b3883d81d4082895887e3db |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/keydb@sha256:1bc83b21c7b48f7815aeb0b1fe90699632a3d41c663e12f77785e773332c5c44 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/keydb@sha256:b58008cb74edbdda3e53d07483f99bd1be59643473d1f200fbd95b8036cbb5a6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/keydb@sha256:dd0a16f2a4313190646e698ca17f97690f2b64ad0b96756fd79a4d871911cb13 |