Sign inSign up
KeyDB

dhi.io/keydb

KeyDB 6.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

6-debian-dev, 6-debian13-dev, 6-dev, 6.3-debian-dev, 6.3-debian13-dev, 6.3-dev, 6.3.4-debian-dev, 6.3.4-debian13-dev, 6.3.4-dev

Index digest:

sha256:2c546188f99828a952347531f8482a19c524cd1eb16b9b11cb5b6d880d17054e

Manifest digest:

sha256:27cee62e5bff8d7cd77ae169f03a8cc3b80fa16491652a26ac114e589f1fea53

Size

32.34 MB

Last pushed

5 days ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keydb:6-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keydb:6-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keydb@sha256:f4055b939aad6c55cc53b39c7197cb9f77b85ef9dc160b90519fee7f5b79fa6a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keydb@sha256:01470a9fc1c290d96268450041e61fdabc736826eb2e97743d66276c43f1acd1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keydb@sha256:d92d5053a7de57a1db89b5cc5b95ff8de21cfda5a7a098d539a7bc6844fbeeab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keydb@sha256:7f8f06487975861f5e2bbce82808b13db6a696dc72b88cd2521fda58aeff37d4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keydb@sha256:57e65b8dce5e6240aae86bbec4617238d676c24d10db4a40d830017f41bb2d50
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keydb@sha256:d521d67e23ea438ce6634f2ec45db7e174ec3c3e6e36b0d42f4f1d7372834100
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keydb@sha256:39e068465b9db7feb7c419f6acfa8fe843e4b1738892f23fa4751073ba307ffd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keydb@sha256:05bcbe1ebbe57be7405ac049ae37297a8caa6c6156195a46c79730584fd6e494
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keydb@sha256:41d7ffa8a6e334fbd2305343ebb6086d8147b6fe7254ff07c7d561f9387398f8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keydb@sha256:cd55cd512649b1ca6a4363b157cf8a85fbf62da00d091d1ccb08c61598ff2f11
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keydb@sha256:57eafcf7de16b5e125eeb6f498b4ae1b3b39119dd01c0e8324c318689e8b5719
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keydb@sha256:2f4ee6c5e4861c06519c02416fcfc9d1f3fd51cf25181f3f5f4c07bb3b1ce614
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keydb@sha256:d8c50e2095096fcc57e676da3e7f7ec6dcd8115b2057fce7e30ee192a4ebe963
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keydb@sha256:b2df5df53bc8d6e7f58cb33f501613d7114898abaf4f844eeeb77d659971c705
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keydb@sha256:76f69162885acdc07f4e9f19b73c5831cb3f403fcc15f1c6d27073611c7d6fa1