Sign inSign up
Keycloak

dhi.io/keycloak

Keycloak 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.7-debian-fips-dev, 26.7-debian13-fips-dev, 26.7-fips-dev, 26.7.3-debian-fips-dev, 26.7.3-debian13-fips-dev, 26.7.3-fips-dev

Index digest:

sha256:b45ffd1cd313bc293da4eeabb2fc2ea27045fbf9b5036add6c4874889464c75d

Manifest digest:

sha256:a79225a15034e4af5b8c60a0d585092eeb521a31a18b7e2490d634659b7a60d4

Size

339.99 MB

Last pushed

1 day ago

Vulnerabilities

1
5
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keycloak:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keycloak:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keycloak@sha256:54a1efb4ab6cc9b6ce51146a3e8900c1f5f433bce408cd37bad43d1e36465157
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keycloak@sha256:9fcce9000c477ca6bfb56a94dfe10cba95dc03d7bec0f56dd094255bdac0a9f0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/keycloak@sha256:550fa115796c0d41b6f27b29d0b9cccf3cb915792b865eb96cc130b814289e7a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keycloak@sha256:d3f294f9bd0c6c3907dfc107a2d975e19c103194e5cae5858c28f031aa71b4ae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/keycloak@sha256:26e5f2a3a390d9796202fc85278c0f2eccddf997de690e1a1027fdda3f8d63c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keycloak@sha256:fa10b08b0a0fe3cb2fa1cb67ecc1213747a9d6232f969212f6372919c0080c8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keycloak@sha256:4dc65ffd396f5a3289c2cb51f431716857530cb1fe2a010a643f87dfc3050fb6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keycloak@sha256:3ea9f221c14320b93397aab79a995eedf30079422d6d9957de9649cb506b3971
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keycloak@sha256:d53bab01796d4ff7881b256aa8ee4e1d540b40ba04306ecda36e68230402519b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keycloak@sha256:b4f56f59075b44042236bfcbbe003d400ce146d74471c87bb1d4c86d7578dc01
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keycloak@sha256:e9812eda10bffbe382a0fa79e849b706d6cfbb128f09fb1b2e0a140d868fe0bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keycloak@sha256:576a36417f4075a876ae877270ee1d75d71e28ac0f3e13d7ac4a8f9ad444fb30
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keycloak@sha256:d7b2c701dcc4b5e0ddcad131f140cc228dbe397073f7507d48ce81cced2fa1ba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keycloak@sha256:9b972ebe21c9ae77d49104aa267969e0dbf96afcba05facce2e85a09c70b0fad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keycloak@sha256:99b96986a1d900565d672abe7c65a462702218abaf405ffbb20a0d3b40452ced
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keycloak@sha256:deed670902e92ccb1d864d13a5cc44b5e2907071c0cd66a821ff39e598b48047
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keycloak@sha256:3090c596173ce3513a3f1fdd259f46c63b5a220f17d4b49279e83d8e0889bab3