Sign inSign up
Valkey Bundle

dhi.io/valkey-bundle

Valkey Bundle 9.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.1-debian-fips-dev, 9.1-debian13-fips-dev, 9.1-fips-dev, 9.1.2-debian-fips-dev, 9.1.2-debian13-fips-dev, 9.1.2-fips-dev

Index digest:

sha256:2a882990135a11fa8814060b0cdf9b77d580df530683faa764236f226acd537d

Manifest digest:

sha256:204675b6a7fd27a6b6a27957c701bb394f7228da78e9f92c3077daa92e0393d6

Size

77.83 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Oct 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/valkey-bundle:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/valkey-bundle:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/valkey-bundle@sha256:b19821a41704dbaab5f51680543d155a51382bb75071ef9cfdd34f4659baea1e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/valkey-bundle@sha256:ea66f40f3f68c2335784839e9745fe853f315fa72cd452a731343f8bca6bde78
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/valkey-bundle@sha256:7455e231b01eb63e920266b8e6f87d9c0b8317f5bdbe0fc6ce0c61f7aac79d01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/valkey-bundle@sha256:24c8b571eb759ecdbc227c386ceb70c5f0c70293c743692044969e866134a863
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/valkey-bundle@sha256:bc6989e194ed65511361ad8121a29877e183d4b3f52aef716626b957d7afb576
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/valkey-bundle@sha256:100a2eb5249ace991a3daa6430b0a0f3e6b0aa69792b4fd12e81ae800e8dff3e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/valkey-bundle@sha256:5ebd5f274c577043fe179400a17620ab07f12e7bb3cce2daa3ee414ee0086c00
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/valkey-bundle@sha256:3bba1791b331881ed471a7ccd7f75a6e4725d4a9c2c1620801bb80d226aacc9a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/valkey-bundle@sha256:f4a998b4e0042365dad410bb29bc51552324399b77e19ac52ffb14313bed3c25
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/valkey-bundle@sha256:e5140cfed02fc22b0871b723fc58c2d6171f6e239e59d5ef8f58afdd55722d9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/valkey-bundle@sha256:fc2bcebeb8fdeec920c43dabf3d87ea0b4d81ba6efcd49652718c042f68dca3d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/valkey-bundle@sha256:f1644b12e73f9f261873b1293ec41e8bde05f4708f936138e4e22017b007c6e9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/valkey-bundle@sha256:f6b136ee645a9f10c58e49c35e8a0dbe15da4a41a91f8efacb7c69ef500f1f38
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/valkey-bundle@sha256:09b48efe54dc63bdec1455ac7473620ed10f45e733726379eefc6432c62d055b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/valkey-bundle@sha256:c4ff22f6ab118ce813f7912451e22d4522feea0dacc060d0a627ff1a4af5a4da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/valkey-bundle@sha256:b1acfc743b7fb1861514e5afa2f6eaba578e96da1f060cb2b55e2013b566fe2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/valkey-bundle@sha256:b67190bc16a08778887e69b941ff1cab5088eea486607d38f38c984369bd6f22