Sign inSign up
Neo4j

dhi.io/neo4j

Neo4j 5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.26-debian-dev, 5.26-debian13-dev, 5.26-dev, 5.26.31-debian-dev, 5.26.31-debian13-dev, 5.26.31-dev

Index digest:

sha256:24d1284b95fbcbee1cf578ee6190af2b18463a19bd20b06b4add2230004ea1d5

Manifest digest:

sha256:39c2666ee4bde1e59bdf77d38817d9f8d338712ddcfd146b00bfa435cb231a22

Size

173.78 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/neo4j:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/neo4j:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/neo4j@sha256:44c8e2877f6c970e44aaaf667480d8ce70e057b806cf80c77230d75805c0352a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/neo4j@sha256:e694c4c320cfaed215fc97c7f298e2b1ed22c91ee434f346c1aa7739770f502e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/neo4j@sha256:466e01452a7f2d71d5793fcc422cdf509e6461a264e1588751f95ce9d52efbb8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/neo4j@sha256:f5c32900e401771893d7a4006cfdafe82f2dc8af23846f5bdb13e29d95fa4dca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/neo4j@sha256:fe28bbd6f3099584873ff1656f004c003fca8a8a40d5d08cdd25c7b4768898b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/neo4j@sha256:25ddd01d952400ba4e72fb712f4e81276ba0de91d91d6d854c8c935685edf8bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/neo4j@sha256:2761aabbbb0122c59b28b1be7f207e7ac54d9bab113cfeb0fcc75dd1a0959bb6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/neo4j@sha256:73d027abcefe52bd8616e154c770be4ca2f07f080d04ea0d0eba52c4e812cbc1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/neo4j@sha256:fabb3775c0585da24b1a6ab97ecafc2e28071a635f94a646b302ec82893b2569
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/neo4j@sha256:4290096037860e308fde5e22a225c4260454c427e2809831bfd2641ea41bd6aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/neo4j@sha256:c2f3a457087c488a20f63ab7f87913b4b622713da438d9fe40520e4e11bd5da3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/neo4j@sha256:ff14ed5e4e3025313e222c35228a4968fa636fa3a5696eed696ec0055b9f8c68
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/neo4j@sha256:ef8986620c4b52b0b09f667857d81e9d85ab746f2affa65f68c9d628a23c9af2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/neo4j@sha256:dd048c7a92b05f87e8404e95d67eb8e3c7437e28cd18fe17b513dc38166dc5c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/neo4j@sha256:9eeb876ec7259ed92e5eeaf8d56622dccff0d657ab4fa1b6da825a8a0de9389d