Sign inSign up
Neo4j

dhi.io/neo4j

Neo4j 5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.26-debian-dev, 5.26-debian13-dev, 5.26-dev, 5.26.30-debian-dev, 5.26.30-debian13-dev, 5.26.30-dev

Index digest:

sha256:d03ea7bd63b5150c4a78ae4343ff4f05c2777ee2e458bf4df6bf3997e7437e0e

Manifest digest:

sha256:b9af2058bcc08a1fc2bcf27f570d75f493916925253c1e54c283c7a6ef625a2e

Size

173.59 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/neo4j:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/neo4j:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/neo4j@sha256:4ec8c4b104501ad049ec18df48a17e7ffb29dc461414dbcf885e9ea996f42b73
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/neo4j@sha256:b2986572405a7542ec4c27cb075e31a1a34e5221062918f25f7e7d29f708aaf3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/neo4j@sha256:29af4e70b85ac5ac8f1d7437304f9aa379e4785293ae730a8d07115f18922ce1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/neo4j@sha256:208208397ab0cd6d61ffb2fa9f765903938ba3af936a56f41015d18e4507ee37
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/neo4j@sha256:c38c4d9c9c614b204988fec1c235f2259c888c9598b07300d8aa160c5377aa08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/neo4j@sha256:8e9144db6693eabaeea3f749df0657455479df7d1f33da19c80b39431cd19ec5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/neo4j@sha256:7b7e064f6ea3b12d7e104806da98c20a46ed8881699eacf00a9e0530c7ca1a49
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/neo4j@sha256:ccf165eff57c3387b80dbe2c7deeba0b264dc7cd454b67978936acad27c25802
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/neo4j@sha256:b6585a8efc0def0c3a762e1506bd0160c453392bd2b85571e428a07a535134af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/neo4j@sha256:a7d8bb68050505d6ca80d8cbd25f8e48527086f48723a1c37d393abb3f1101e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/neo4j@sha256:89cbd89d077b50c17f78cbb3193a2003dad342dae02ad1142c8ee0640d2272d8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/neo4j@sha256:4df05bf174b52007a91358ead5a5bfde2d000ebef4b43a220e42bf36e9cc6a80
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/neo4j@sha256:507e7f47e2101fd3cbab0ac82aaab32390100ca7e806563fb051592eea7a8d18
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/neo4j@sha256:4dc5aaf1d3707a141b1bf02a926a7c5e56b5e56406fdce00920f6d18ef48b9b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/neo4j@sha256:e77b81b0a8d4272c0c9fd5815a9f522ecd9d0d3fe937cf66a291193c6c5a1854