Sign inSign up
Valkey Bundle

dhi.io/valkey-bundle

Valkey Bundle 9.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.1-debian-fips-dev, 9.1-debian13-fips-dev, 9.1-fips-dev, 9.1.2-debian-fips-dev, 9.1.2-debian13-fips-dev, 9.1.2-fips-dev

Index digest:

sha256:3ead11cf73f510d36aa3d45dac13f5829feaaf0b4ef99bfbad7715b4b8baf5f3

Manifest digest:

sha256:97e19e0da13bcff108393f8e77d496b5bde0a43d36c9be72b368e1129c104626

Size

77.83 MB

Last pushed

2 days ago

Vulnerabilities

0
1
2
10
1

Support

Active until Oct 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/valkey-bundle:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/valkey-bundle:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/valkey-bundle@sha256:da6e8dbddf091370414a3775e9e28832e02ee515f589c5f1269ee0552f597a36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/valkey-bundle@sha256:70255fa45ceaa12b0f6cdf8dfd17688b459d7fb36808819643e0c2cdc9f5324e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/valkey-bundle@sha256:f5498c48d6be780ca1a75810e0463483d72b8966821a6b7bfa780c77143f6cbb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/valkey-bundle@sha256:e4eda60907e7cf556dc713985f395a848ff3f910e59bf98ab752e7eb646ec3a0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/valkey-bundle@sha256:a5a35a061d5ca2a287ef28a801262b0acf34f098192173275e6b8bd093832aca
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/valkey-bundle@sha256:05ed3fa028d68c7b668d9605022d0318ee260d4c57749362b24bb7330f9ebfad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/valkey-bundle@sha256:066681a1feb1595b25368d7a78b1aa09cdb15377782bde9a79ec27a62b39525c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/valkey-bundle@sha256:11a931558af56c42f5404d8d9ba584726008144ad757063419b33ae8e88cfbe0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/valkey-bundle@sha256:1d2355c4d89a0c0d28cce14093713b1ae666b4117d0fa6a671c02aca323e372f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/valkey-bundle@sha256:47df3033bee36feebd01852c8d4c260e077d2c50660265d80d456dc228182649
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/valkey-bundle@sha256:fe72e53c2c15edbcc03ca4712d7d24e2ceadc9efc2ecb6e5ba09922eef8af772
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/valkey-bundle@sha256:688fd63ad6aaf36b624cd12fd144722f4ddeeb01da556e54802f60de908a3098
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/valkey-bundle@sha256:f53dc9a83e5ddb9e50e76d5cd55c51534ace63d33d1784dfe39cb26d62fd3ce1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/valkey-bundle@sha256:d7055c0ea04693ee151c9f34bf0ecde8104898446e858a55c991c5cec11eeaab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/valkey-bundle@sha256:39fe2ff6efb27d9e799c293fbe1c3be366578f085dc16fd48994b332a909c284
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/valkey-bundle@sha256:cccaebd66a221626b0ee261773e1b790c0ab52bfd505ccada495dea46e9ba5f7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/valkey-bundle@sha256:9aa9cd06158e67f5be6563b482f62b31af48b9a0cdadbb69d5d89883b3ebf9b5