Sign inSign up
Keycloak

dhi.io/keycloak

Keycloak 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.7-debian-dev, 26.7-debian13-dev, 26.7-dev, 26.7.3-debian-dev, 26.7.3-debian13-dev, 26.7.3-dev

Index digest:

sha256:eecf2f6c48233d14bc069680480b6940966368bbb2f28d55d2fbc39f163b5aff

Manifest digest:

sha256:730eb11429921674a30cb6f43237ff695747fd6add33aa0086f61335ccadcdbe

Size

320.07 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keycloak:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keycloak:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keycloak@sha256:bbf3917ab3435e43397eb4bb3706f403b0abc0a20bcf2ccd3829e0380c8be164
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keycloak@sha256:0213274e63559a14e0006254776a56586017b268b2b0280bc1e9943148245f3b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keycloak@sha256:1cfc42657f3b5edd42990d79ecb93203a707ecf52c65bd185e9a1278cc94d1fa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keycloak@sha256:edc8e4ad46d77ae8f2ce170bdaa2d60817d4eb51565b4e5a52a53ba52dd8f3a5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keycloak@sha256:2073e25e0fe8b095c83147f8869e73c5053f0e3d3b4f3f7ff6944b11e49b7682
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keycloak@sha256:5c0e8e28ec43a93d1b0821dc01f6cbf99d3102d1c4a5bd81be753dcf432b39bc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keycloak@sha256:b6961748aeb31de0dcdb6104351b68ca2dd0b2a68d3d95002d034f72536d6922
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keycloak@sha256:15ee74d6a6ed80ac18fb1d95e57763e455dbaacdc88ce18427522004eb07c5de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keycloak@sha256:90e561cc708601272c3e50d3200ee3a5851e79d141293de45ca3186d4ba92dca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keycloak@sha256:3a83554bcdd387e5e6dba77254723fcf8e7d29687f4bf4e90167c7e4b85d847a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keycloak@sha256:fc10899f6fd779d7b3480ef9a8aac8159e321bb52d77d0b9dfd91178d1b8f4e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keycloak@sha256:a5b25a129bf84c3add70047a0791c9baf91462ef86df4d1bdab7a9a7651f4633
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keycloak@sha256:3c1b2b693a3225cf108c8dc891e909443991b75cd9f815fdc46cc3c4c110d47f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keycloak@sha256:5307823f6b5364f2bd6d476751baaa990c875969b17dd06199c830424f9fddf2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keycloak@sha256:a9d7b9714bbd0cccf4854d82cd6e69680c8648b021430db3ea8773fa7cf97c9e