Sign inSign up
KeyDB

dhi.io/keydb

KeyDB 6.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6-debian-fips-dev, 6-debian13-fips-dev, 6-fips-dev, 6.3-debian-fips-dev, 6.3-debian13-fips-dev, 6.3-fips-dev, 6.3.4-debian-fips-dev, 6.3.4-debian13-fips-dev, 6.3.4-fips-dev

Index digest:

sha256:29532e9f2c442ad5f4f0a2d60437e738098263515076780c7c3616cc66e7765d

Manifest digest:

sha256:e6bb7252b49a383590ce7788393f7315c4933bab20ba9abb7e5ef5887b095863

Size

33.15 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keydb:6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keydb:6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keydb@sha256:76aefd359c1c8cda84dc6c78b1119c7b638797778ffca147476bd667b0162ce4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keydb@sha256:47a5a18d2e269460d14cee42dc819c12d3c5f4538bdd3fa303434052b425744e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/keydb@sha256:87049b0b339c5553bcc92f470f69a07add829a2a4ade3b61cbeef46abf4c1d26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keydb@sha256:6c090e350c96d5742083dcd4fa82df4ebc0e8149cacb39bf0372ca9966c14eb9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/keydb@sha256:4127efc9490fa528f3dec4a80546801fa69dfe322f10dcad7e7ed99b0fe58b5b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keydb@sha256:1b9cf0565a7e38cf84a69c12d0e2b34f82ced5c3396ee1136a836789fc07dbfb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keydb@sha256:cb2255c34c21242febb8c280043d9291a556ff9c04856137127e332a4138be03
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keydb@sha256:0fc8fe07e08243651498a4ac565b43c3f13a6c32c3e6cf293f73c1a8f6b5252e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keydb@sha256:ecf3c00dbd06273d2e2298605f706f028bc71b1da578de9ea9574a8adfd44955
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keydb@sha256:12dccc309a0272fca988353cc3159ef5c1a401350536e309056deb1975328dc9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keydb@sha256:e4c9f85b858f17f99f7a874726152d425b14f9be9ddebd6350639ffef884ef14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keydb@sha256:f855c1cdf3e3216d8c90e475330ee34bf7ccd688ed8d27b2c4fa54521ff2d446
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keydb@sha256:3966dea07d4aeb127f34d67dbbb38aee2f5d6f69a3cca339d40ca8109edfc46c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keydb@sha256:74e911b4c8b0e566a4caee7d92c9d1dfdc1ccc3a4a411494a530793a8b00b50b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keydb@sha256:45983cb5a69d222b24269adfc2ce14c849a9e298573512e8bf2642bbbfbd3b53
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keydb@sha256:153e74af84250c3abfc60647a2d1f0038f60318d7d420f044d09b17673665498
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keydb@sha256:2e4d893943ac8a129961ff893c96e80dd2f7a5db19f2d4867625efcb423707be