Sign inSign up
Valkey Bundle

dhi.io/valkey-bundle

Valkey Bundle 9.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.1-debian-fips-dev, 9.1-debian13-fips-dev, 9.1-fips-dev, 9.1.2-debian-fips-dev, 9.1.2-debian13-fips-dev, 9.1.2-fips-dev

Index digest:

sha256:413b95a4c1f0631c5b18fb1cb09b89cdb602e587c5c8c0f93105e3d6f7acc198

Manifest digest:

sha256:01f2b02b38d01f7a304358913f04dac95dfbaf37425e56f4fb754b24afd57795

Size

77.83 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Oct 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/valkey-bundle:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/valkey-bundle:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/valkey-bundle@sha256:f055653db20fd079a2d7c4b4fab1c09e1f04aa03315feb3a2978c92eebd20bcf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/valkey-bundle@sha256:b9f8db664976ff5f26eecee7b82f8b87bf73389b398170e6ed1017f72a4a554f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/valkey-bundle@sha256:55958179418fdd5070f16b0ed73f051f43ce8e9e7b51fd0652709488731e67a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/valkey-bundle@sha256:7a78650029bac4043f125fb09d74bc052093237b718bd810193db30b4900f3e2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/valkey-bundle@sha256:70b7e90767fd38aae133a7bba07f2783f7a40719975a69967aff859a9ac47e79
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/valkey-bundle@sha256:c737c4c189a68602059898b2698c3fb4a127bf15cd5751f9fcac84a053dc7ce0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/valkey-bundle@sha256:241afd13a890c331625e1e56a7c8371370124581d16b9349cb6d11614c8e9672
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/valkey-bundle@sha256:b9f985609a6ae79dbece1450f0fa73ec79a36dcb77ef9c4d88551673e80213f7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/valkey-bundle@sha256:aae473d5c947947b5076b4a87a77d74a5c81ea1ad7cfdc49db54555a6c7e9eec
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/valkey-bundle@sha256:1dcd757e5f9642c65fd8ed73f3ba491e374aea34eb56563dfa04665974b91d32
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/valkey-bundle@sha256:4f58ff69c76427f28014eba11eecf2c2593a76a876946fe1812b40707504b510
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/valkey-bundle@sha256:89d705bd792b648c6d8dade40d61d3118b2a27cf29cafd873c8d0fe922b0c016
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/valkey-bundle@sha256:6073972fb0cde404f7952e7fdff498693fffab772aa30e0ab50d7324434f16e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/valkey-bundle@sha256:7b2c6a69ab057365df2c119962d5e57914591ba3c6d591e33bdcfe9875c56495
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/valkey-bundle@sha256:f17d78e5b65fd0edf3535ab75690d0db511aba2aef2f09d4d98fb0a2a1aa98ed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/valkey-bundle@sha256:75a87e3b0c0a1ad33c1878d4f0c9b5d233f1df1b266782524239dbf324a6c2bd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/valkey-bundle@sha256:4b620eb33717110bd7b7a1bfbafc033a94eb52318eb6ff9717e0b64705dc0dbf