dhi.io/neo4j
5-debian-dev, 5-debian13-dev, 5-dev, 5.26-debian-dev, 5.26-debian13-dev, 5.26-dev, 5.26.30-debian-dev, 5.26.30-debian13-dev, 5.26.30-dev
sha256:1196b04d7a03d15d08fcfc0b6ccc182827a9deb2da4bd69c22c238962b6a68a4
Manifest digest:sha256:86b7c08470125c295692ca5e4cf6d4ef4e0f52c3dc6b6bf4d21260559c4b1352
Size
173.59 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/neo4j:5-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/neo4j:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/neo4j@sha256:04252611b60f3c01c0c3d8ac3774361bfd8630c24894a281a43e80a01b770496 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/neo4j@sha256:d700a3d676020fe2c23c871473e805780667ff2cb24e18b87dedc3e087e0040d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/neo4j@sha256:efbbbfcab6ca87d2c784ac3de427ae98d6096c6fab2d6ad3937dbdbfe93a34cb |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/neo4j@sha256:8ecd4403b205a89f58f84e553cad6dcc966bad4003ef018484387a05d034f8ae |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/neo4j@sha256:0d0f5b2c2f6e0433cfd713b8979e7ec6186adbe5a7cc8b720f610e9c8612e56f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/neo4j@sha256:2f7e95ed336e52d47db23d9ec617bb046c6fcacc65b70d00e44e7442234c486b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/neo4j@sha256:0d6672f1fd8794c489f1f6a4de849aa459f25b7237a8290ae26aff0172d61942 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/neo4j@sha256:87c6350c14e5db11e1e568b1f16f9273b2b027c4682fe50fc1709c1e094d1bb6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/neo4j@sha256:62b0205ee817484931ba4626ae7a1e5e73c19a63e5b61969d1e9a4f327b4f79b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/neo4j@sha256:8afe0f150d95eda8061edd8536127ccdc155d37d2f11195429859fbce675e415 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/neo4j@sha256:03f5c50585070b6d99cc15637149844a7058680099ff70cc44c20e49d89c82c3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/neo4j@sha256:e0410439d88a5b0f632ccebce6c9076fd9667e980a0080c0e6f510eae37adaf8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/neo4j@sha256:86751a8aff167d64be3ee5fd034d4cee8b7675d5da2921a3a47e57eb844dbb51 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/neo4j@sha256:c70140def6cb752e4a68bc9b0cd9a608d834dfb2aee677117b1d460af4efe212 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/neo4j@sha256:3b7c9d5321dd35d19053d4230ff4769aee1cc0fe293425bbdf8c6d15f2154831 |