Sign inSign up
KeyDB

dhi.io/keydb

KeyDB 6.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

6-debian-dev, 6-debian13-dev, 6-dev, 6.3-debian-dev, 6.3-debian13-dev, 6.3-dev, 6.3.4-debian-dev, 6.3.4-debian13-dev, 6.3.4-dev

Index digest:

sha256:481cb90d3de2cb827054fd9cd75a21cd239e1795aaeb3cba37c48209f3163460

Manifest digest:

sha256:1bc2188da84a91ce712987235e1e40559e0d8766e149a9ce272fad85b5f46c03

Size

32.35 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keydb:6-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keydb:6-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keydb@sha256:82e3495f1c878014a708bda75632ed34d12c701fe5766a3552d6fc54eecd2b15
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keydb@sha256:feb4bf6fe06ece71f4b4d6697ad662d160d25a0ee4c62be0690090475a5fffea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keydb@sha256:7c189bf1a4b73141328acb04fce7c0b952bb0204360b1560ad75708b14822f05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keydb@sha256:e2438f67b9c1a40a5f7f0a8114c5bc6630999aa64a39af89e8320e604b1e432d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keydb@sha256:11e00458671f0493d8fe997fcd5df240f0d3a1d151608a3b0c22b125fdd0aa9f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keydb@sha256:24f516013b4a5f5a22343976c7b642404a6772b2287009ebafd03ca6f1c6450c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keydb@sha256:6c79f4582ff13a4aeec16a68dfaeef6acfc893e8103b3632fe6b6e7d1decd7e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keydb@sha256:6011fa0a21e1320d620721795c909bd823ed77ee0d74f2c6d46ae602f30b677e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keydb@sha256:611ed82b4125ed3b490186165dbbef2b9274179f15ce3eaead5ecb84de8111d9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keydb@sha256:75636eeffc52bb7d89b14b029dca2100f8fbedf90ce9799dc648fdb7062ea13d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keydb@sha256:ba1a1989134ae1e54864262b01cab1eb437a62b31642524ba8c690875f5dc09e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keydb@sha256:486ab030f73e0751d68b7e74d05cfcfdc6dad0e703502cfdc4a0a3f4de720200
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keydb@sha256:d2b90de54b7b2b442667f6ea88e32a6930918f4c940c8b9a9534f18c250bdfed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keydb@sha256:35d238950036fdc2b969666bde54aa14137d7a113299b2d108d9f4954c110a31
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keydb@sha256:7299c73e2fd58d18d7cd2e5e9cf4311e6a7da81661f153716b0254cd1dd9d1c0