Sign inSign up
MariaDB

dhi.io/mariadb

MariaDB Server 11.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

11.4-debian-dev, 11.4-debian13-dev, 11.4-dev, 11.4.13-debian-dev, 11.4.13-debian13-dev, 11.4.13-dev

Index digest:

sha256:745f70d5a0d21f9f0ab16960ceab980c441639251cac0e0ca6a151821ff5a420

Manifest digest:

sha256:f80245838989f5b6cf2e78b1fccad881aaa74c0ae30de32da99f52136ecfae0a

Size

513.06 MB

Last pushed

3 days ago

Vulnerabilities

0
1
0
13
1

Support

Active until May 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mariadb:11.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mariadb:11.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mariadb@sha256:e7b6063c90c0cd5fe9186bb774a8245715f8e0397b4b7be219e5ce5d551dd2c2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mariadb@sha256:6c8dfad69066dd287107b40db35c17c846745e3aff1c1cfa9d8a6efb6d21e180
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mariadb@sha256:7307a844c2d28df21415afd555a905cd425115034a6a8f9d5035384d817cd73c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mariadb@sha256:ed858ab02d120a3b0f30dfb0ea8bd44e264cc13010e53f3e59be5f7a92ad50d5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mariadb@sha256:6bd4dc0f8d458c95cc24d9ab9994148fae1a422e55c7a20616245e7ef0e10174
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mariadb@sha256:7b4ca4f49adfd75dbf32d4b44b529238edc0a1108bd1ea2b820696f8e7c20aa4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mariadb@sha256:1ec9b29e4a5ad8250f63e4b946e84e600fd49e3f945a1cdf55a488a92f7d459b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mariadb@sha256:6c661c64baadd0d7320399ad8168fbc5602e9e30b30bf1821f8523ca7b8ab0fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mariadb@sha256:3323ecfce0835f1b2514bf0dcf651a8705e75843b459574cbaece0d52464b9f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mariadb@sha256:c8abd2b1545cd889d2347a1016720369bb804e0f46bf7c9fa70b656d9c275b1f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mariadb@sha256:508dd111cf04c61fbb8633b8de2b406176571bee74bdcc1f94b2ad34504329c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mariadb@sha256:68298bfd6b16c36cef3b233b4f45d6efaa7029c3ecb7ce8cde8878467f1e9c3c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mariadb@sha256:4e91e5683c8d8d14ec1b60d66f6e810d0fde9b37bacae921fbc3753703fd798b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mariadb@sha256:ff75f6e0cc61678a36cb957e7552745273056c3c2aad2db5966894b761be3183
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mariadb@sha256:61b9861e21ec7d288886408682f0fe2f87a62dcaa204274f36453c4d5b4254e5