Sign inSign up
KeyDB

dhi.io/keydb

KeyDB 6.3.x

CIS
linux/amd64
debian 13
Tags:

6, 6-debian, 6-debian13, 6.3, 6.3-debian, 6.3-debian13, 6.3.4, 6.3.4-debian, 6.3.4-debian13

Index digest:

sha256:742b52382cc4c8463026350d3e75d9337b53def6c77e8365fee082280e24ddc1

Manifest digest:

sha256:c5ca40704953a7abbc07f2b20449110b07f275ad9852590540ef69297efcf844

Size

17.95 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keydb:6

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keydb:6 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keydb@sha256:a9e5b5bb99350f34e4ff200f16f9210da208f532b8061f83fafffa2f96138507
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keydb@sha256:f1a0f984b2603717f85e6731f11e69247c5322066d80e7cdd15c81da2fdcc98c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keydb@sha256:3e2ed691b6ec6e3f5b336fc9bfd9fd64ebce05e0e17fa0efe27a9905c154c6e9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keydb@sha256:dc7a849679a91d54fad73e9b58b4a5b86f3749dcfe101b0eadba43dd52e119c2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keydb@sha256:b6ec8cce21aef9cc8a766dd4e3d5aec97ecd00b1f9607336b2f45cb4f971b714
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keydb@sha256:593af1acdde62864ad0f5bdd00f47ff77a6a5b326bcf3b9101cc4a2a9190d3f0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keydb@sha256:b2347297dbcbb5fc909c2cf7f54dfd3f66787dd79e8ffde024ea3ada5af85aa7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keydb@sha256:089c4d57aedf17ec1ba39cf7c14075b41d4b24bfe1ee363d379efc64a8378dcd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keydb@sha256:e9517af0536666006a7d78cfa3ff75a99959d473d374f49bf84669c5362edc90
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keydb@sha256:68a5c900179fa848c6750e007eab86d0af006a925098f8667ed2cefb30a1dd5b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keydb@sha256:67c69b500776289521b73cefc48a60c39a810ec50db6de9550d96eb117837a85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keydb@sha256:036d33f58ece40c6c7a706de87e05a5b0388f53a3b3883d81d4082895887e3db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keydb@sha256:1bc83b21c7b48f7815aeb0b1fe90699632a3d41c663e12f77785e773332c5c44
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keydb@sha256:b58008cb74edbdda3e53d07483f99bd1be59643473d1f200fbd95b8036cbb5a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keydb@sha256:dd0a16f2a4313190646e698ca17f97690f2b64ad0b96756fd79a4d871911cb13