Skip to content

Dependencies

Images6 container images
Stock (DHI)4 images from Docker Hardened Images
Custom2 images built by wellmaintained

Images

ImageSourceTypeAttestations
postgresdhi.io/postgres:17@sha256:99cb610d5fad...stockDocker Hardened Images
redisdhi.io/redis:8@sha256:ed5e2e3edeed...stockDocker Hardened Images
keycloakdhi.io/keycloak:26@sha256:f1aa59bc953b...stockDocker Hardened Images
caddydhi.io/caddy:2@sha256:bebd9b1b94a0...stockDocker Hardened Images
minioghcr.io/wellmaintained/packages-dhi/miniocustomwellmaintained
sbomify-appghcr.io/wellmaintained/packages-dhi/sbomify-appcustomwellmaintained

SBOMs

CycloneDX SBOMs for all container images in this release. Each SBOM is extracted from OCI attestations attached to the container image and included here as a browsable component tree with a downloadable JSON file.

ImageTypeFormat
postgresstockCycloneDXViewDownload
redisstockCycloneDXViewDownload
keycloakstockCycloneDXViewDownload
caddystockCycloneDXViewDownload
miniocustomCycloneDXViewDownload
sbomify-appcustomCycloneDXViewDownload

How SBOMs Are Generated

Stock DHI images (postgres, redis, keycloak, caddy) carry SBOMs generated by Docker Hardened Images as part of their 15-attestation suite. These are extracted from the DHI registry at build time.

Custom images (minio, sbomify-app) are built using DHI YAML definitions with dhi.io/scout-sbom-indexer generating CycloneDX SBOMs, plus SPDX SBOMs via Syft.

Previous releases

Historical releases and compliance bundles are available at GitHub Releases.

Last updated on • David Laing