Sign inSign up
Varnish Cache

dhi.io/varnish

Varnish Cache 8.0.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.0, 8.0-debian, 8.0-debian13, 8.0.0, 8.0.0-debian, 8.0.0-debian13

Index digest:

sha256:98115b40d7a745c9e8213329aa5b569bafb1868c19e700d0a963fe67e1733a5d

Manifest digest:

sha256:9cca5958a1f842f401c86a033dc1affb014ef20c6362843987a5cef023849492

Size

72.22 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Ends Sep 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/varnish:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/varnish:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/varnish@sha256:9bbcb95544122a20de732b575cd83a57b39cb132732d354393b292e1d21a2f9f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/varnish@sha256:578990db52397221c0ddeaa8b493546988cceeca65bab9f4071733a1c00f280b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/varnish@sha256:335b1963b15c78c5b8e75739cfeca98f79871a43b30149c5e098e42a64ca8ba6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/varnish@sha256:62231555d8a41ece1121dce88239dd118afcd326234c62c0a93b27f72eb88e31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/varnish@sha256:ec2f4038f73258d9c7f3c50ef37fbecf0659bb3c1e924ad7549d24405a220be6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/varnish@sha256:23dd69fc57f1ed978fb22ca4c333ef217c926bfd4e6cb0fb5fe7ebaa7d72b0d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/varnish@sha256:3f2713fb8d4c5a38f3039099872587a2ab9602b932946aa2c009dc904e2b8950
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/varnish@sha256:36420dde9bc55325d56873fe9ac0e89b0182fef099a2131809631ea0399d7901
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/varnish@sha256:a6cc81d87ee7aceb0215a451f692ecc21d84fe3a7ac4e5d93d66b2aaf7b0d4c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/varnish@sha256:5b9b8b7f9357f830be7d8c74f5d4fb6463ad7a0e19b5258aae092f8edcad434f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/varnish@sha256:215ba41cad744e5b9c058f10425e858f7b5dfbaf4822830278bef2d268a749c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/varnish@sha256:2f50272b0d0b27360921e87e144cedcd8881b017eff562a3e2cbdb1525c34ae7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/varnish@sha256:f32a02549e30335dbac7cbc1241ddfe1536227f3a255719cc896e11b3bca1edb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/varnish@sha256:a397781b9dcdab54d74da8c0c18e785eaa4ab769db01b99014caf6d2e12b197a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/varnish@sha256:1715511cd73db007e3fc86a4968d89473cc8c36684b12866eaa18e231af0851a