Sign inSign up
Redis

dhi.io/redis

Redis 8.8.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-alpine3.23-fips, 8.8-alpine3.23-fips, 8.8.3-alpine3.23-fips

Index digest:

sha256:a33564a69b6c01daf0450ea65fff85cdf814fa34aa907c8ecf1dcb1066b1e7ed

Manifest digest:

sha256:d54961e26a0220a31c1bec7297fc9d662ddf245077a10516408b4a1dd9cb3f92

Size

24.67 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/redis:8-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/redis:8-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/redis@sha256:7d4d797e512b0c3414af73f5ce2dadfbe87417c84a0aca59ec57298569fb7bc7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/redis@sha256:bf76c09d7362cc927a77ac8acb6b18e2eccc2c682a7f80ac02823a309a45503d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/redis@sha256:f4791b7b4bc78cf5bea9fd9d115a098fffe19ec0977e01e239b74f2feac7423e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/redis@sha256:715ed5edfaa38a425c97ea7da21e4150941cf3198c22b3934d1f6f9e6601f8a1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/redis@sha256:512eefb867049d2b3355a6823e9d91b89bdb7f43fd452ad532e08348bf8e04b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/redis@sha256:f248500485215178193bdba2bb85b450a631956070478aba2182d3c68ad6c79f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/redis@sha256:d127c012ae0c4c64017b6382e3c71d8cc8145c469e25daeff3610e72cc282d31
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/redis@sha256:0c6e29a3647b59f72d3195192ae5568554d16c153a8c1e7e0b7456b4d4ff82b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/redis@sha256:b0ecbef36de45c1b4d429aa8cd62ed8d88876c11c6465475f2846afd84b47fc3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/redis@sha256:e3c0c96029339fbe7685398510b2e4e55a038a643c7184170241a1a14772280a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/redis@sha256:a593b356ce6d35a08fdd6e4512227b435a632c61f53cb069210b9c797dafa500
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/redis@sha256:265a6bcb9dcdd7ee957247495f97aba70617a7449bdff636f6d23b13358e5dc3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/redis@sha256:226a83d20289f70d964dec4933cddf5807556fa3d0f94fb224ca012b7d6de67a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/redis@sha256:49fa1acbea01c60d07d6818cf94ecb2e365b43fa31b9db54eae989fde8f23436
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/redis@sha256:925111ceed2382e36584f01a30832b97b1ed396e2dcb9fd869d2b426f59317b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/redis@sha256:8369f2549186ce55c38861f3f796b43104e4d468988c7ecd5363e92f70914c2b