Sign inSign up
KeyDB

dhi.io/keydb

KeyDB 6.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

6-debian-fips-dev, 6-debian13-fips-dev, 6-fips-dev, 6.3-debian-fips-dev, 6.3-debian13-fips-dev, 6.3-fips-dev, 6.3.4-debian-fips-dev, 6.3.4-debian13-fips-dev, 6.3.4-fips-dev

Index digest:

sha256:82036c18adecee9a484d0a6c4dc7a8057f6695a54791ab34efe1bf9f7e270407

Manifest digest:

sha256:02f53d4c95838cae189494262364b4b98ef60505b99e163ff231e91ccd67b661

Size

33.15 MB

Last pushed

10 hours ago

Vulnerabilities

2
4
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/keydb:6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/keydb:6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/keydb@sha256:53c9212b0df9f624c85033edce2fba749aeff4fceb24439cca449fcdd7374a72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/keydb@sha256:5e020f17ec180a5b11dccd8dcc3609685656fed0f7b5c16a9e923d0b6cd058ed
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/keydb@sha256:869dd900d8bce8649aca1aff9f29399c60635347bcebd607cb6972700a4cd54e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/keydb@sha256:2053339902bf73c1569b9097ca494dbfa023215283147e91ebc7907c8308d0b3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/keydb@sha256:17e394b8c614940153a0cb22181375dfb94039318a5737a56e787969c8c05cfd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/keydb@sha256:c0ddaa7da09c573e3d3499d6a3147d32e8c118c0029db39782096e293573f56a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/keydb@sha256:58ea4e5a076a9e0e498b2a3cf34175d6cd274652569a7ead99ca80b811f90881
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/keydb@sha256:1f31523b15679b3b2e44a33df04e625b9533486a0a712317944213e5477ddc2b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/keydb@sha256:f7368d14960f3b8f4886ad0e75293195c621d6e8d8d0860d09c6ad3b52be8635
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/keydb@sha256:00adb699cf476dbc1ded4b10b17512859e8359f01140aeed0db720a962f6948f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/keydb@sha256:fee6d838223fa8c0eb9901751a236a3c1f72b47cab97867aa8b30e031d6b6699
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/keydb@sha256:cabe465fafe09b645a5bfb14aa14efbe1340a823d156c69bece157c0eb975548
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/keydb@sha256:7f17e5b168dca7ef52315f8882250c91cd577a2fd9e983ff10e6a562f0bd0c10
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/keydb@sha256:5ec35c5d2a1f95df71e0dd2f405e41bbeb22f59c6d47ac3ad413e7796df0f895
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/keydb@sha256:6851bfebc7648540145d26787e5aa4e593179e4b1159afa80919a6509b2cebc0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/keydb@sha256:b9285841e4c0278557a2bb0cbbd0b78092acfb0397d4e6d75912d93fcc1ca601
SPDX SBOMhttps://spdx.dev/Documentdhi.io/keydb@sha256:5d452a3fe5fd6c93494167d7d9a9a928dda419758d28a3125265e8bf195cb13b