Sign inSign up
Neo4j

dhi.io/neo4j

Neo4j 5.x

CIS
linux/amd64
debian 13
Tags:

5, 5-debian, 5-debian13, 5.26, 5.26-debian, 5.26-debian13, 5.26.31, 5.26.31-debian, 5.26.31-debian13

Index digest:

sha256:ed066e7621b469a627dfe5c29488345aef63152a473d1df920f24e4b3c4bd5c1

Manifest digest:

sha256:221ef748f79433dd6f5850d16b047c44cf23580843afae87ed64de484f4a3b5c

Size

163.39 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
1
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/neo4j:5

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/neo4j:5 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/neo4j@sha256:b41f252bca2b9ab5d5af546c6ac5eb3ac0dd9b722e636a1623714950d067a239
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/neo4j@sha256:3e589c6efb893b28ebaa7404946114ff32d637d2db08bb86e1262914dbc7682f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/neo4j@sha256:169743a9662722ec7dc1ba1684093794cb261e0f2ba7cb2b0ce5f9cb8626e851
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/neo4j@sha256:54b27545d1e6b2862ecf59fed75fe5e7f556a6773f303bcb8fcbae56c8b909f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/neo4j@sha256:e339c51eaf750f2f6372af8e2015eec2a03f6a946df7b82dbe80a0efc7e274d1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/neo4j@sha256:8e6955bcfbfa912d9faeb3a3e44dd1976cc4fa0900118388c54da0472a0af61c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/neo4j@sha256:59cdc325d5ee0e9557dc971518f8e6a99707ceaab3e89e8780cd278b6a78152a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/neo4j@sha256:2cb589d1708bdeba819b27c1e2c0ef52be577313f9c16136fa14ae01b68f73de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/neo4j@sha256:7250ccc829b755fa3461c0518427c64e000ce9d1b9528dcb2ce1c9772679c201
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/neo4j@sha256:7a5ae5c7a2693a335f52fb3e2806c8812cfacf146150b24f07016bacd0dd503d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/neo4j@sha256:5f2f0d7bc579b8ff00929a9fd1ae51f044dbb406dcf28e80f1be6276fca5f150
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/neo4j@sha256:1657c36553d4846a282d94111ab9bf0ac17d473edf1958505ab62b5480d0ba10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/neo4j@sha256:2704056b1f81c20037c6b3f9c556e0aea99ad142704a58d37f5870658b601a76
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/neo4j@sha256:32cff552a57c243108c0e40451060c001868336d91589ab812a42415cde09416
SPDX SBOMhttps://spdx.dev/Documentdhi.io/neo4j@sha256:a6cf6849b5dc205e8dd48bfd9c314329525c6c834caa893d72e75c487387e3f0