Sign inSign up
Neo4j

dhi.io/neo4j

Neo4j 2026.x

CIS
linux/amd64
debian 13
Tags:

2026, 2026-debian, 2026-debian13, 2026.09, 2026.09-debian, 2026.09-debian13, 2026.09.0, 2026.09.0-debian, 2026.09.0-debian13

Index digest:

sha256:e5919d05574b0113b836c492f043e55dd218a96af5446f6db5c0a3a2a9cc0574

Manifest digest:

sha256:8e3b249412a3485fd9127d4a1242ba74c108f6a4a36d564cf37d3cd8056a3a5a

Size

198.06 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/neo4j:2026

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/neo4j:2026 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/neo4j@sha256:62d6174f24e88ff2dd34ea41c69d10affb8c81616ef215dedd93d123bd222f25
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/neo4j@sha256:b4311a80de766ed05daa239b6dbfdd8fabce4b37850bc341ba45321974d4f941
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/neo4j@sha256:6fbee408fdc4ef140a4e0e3ee0c5dc105b94f4cf855c5ae56a7b5eebe851cd46
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/neo4j@sha256:d5ee12876dc58cca50b5c91b7ba054983c4a26c4a087ceaadad9298fb85d0ada
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/neo4j@sha256:b208c6ee5edcd2e2da73e581f0781a5694bd18a76788414a018d380ddab7678e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/neo4j@sha256:10f0edc3e8e94d1f46e930d78f9b5c567623f843a2eef44cb0703f1315945c51
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/neo4j@sha256:0e9e014ca588572591b77fa346512f90ee7a54fded707ebcc821e444c17c9a0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/neo4j@sha256:7400a36ddddb11100e96d7667fdff4b5a1cb14cc600be6180388cae3b30b725b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/neo4j@sha256:7bff906624c3dfeca049c5a901f57cbab2bf77d1f625d9ab5fc99a734617db6f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/neo4j@sha256:c4ab39ac5c64c94115b42a53d3d728ced07366f6515ec06f146c3e5b0aa3327d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/neo4j@sha256:a519a7f511ecb0984562fd9a839df35714508dd8ff4556f50678118e40a3ae14
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/neo4j@sha256:18ab9ed75dd0376cfc59afaf8df1a9774247112105849a2d9e37b49e3b4dca62
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/neo4j@sha256:aa4d330fe925fc19dc483a70dc655e5278c3a3fe5e4e4b86787a6a7f4172b2dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/neo4j@sha256:cee6c0e06c67291e9c87ea13db6c9703c192bb1f2d8e5f00bc249e6cf5ab0b2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/neo4j@sha256:16cfc6ee9f575771ffa33a521e721c9168c4f14535ac789b3997ce603dfc3a70