redis
Patched Databases & Caching
from
mirror.gcr.io/library/redis
Pull Reference
ghcr.io/verity-org/library/redis
docker pull ghcr.io/verity-org/library/redis
Copa-Patched Image
Patched in-place from the upstream image using Copa . OS-level vulnerabilities are fixed without rebuilding \u2014 same layers, same behavior, fewer CVEs.
Supply Chain
Full compliance details
Signed
SLSA L3
SBOM
Rekor
Verify this artifact
Cosign signature
cosign verify \ --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \ --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \ ghcr.io/verity-org/library/redis:8.6.0
Build provenance
gh attestation verify \ oci://ghcr.io/verity-org/library/redis:8.6.0 \ --owner verity-org
Vulnerability Scan
Found 91 vulnerabilit ies in the original image. 8 fixed by Copa. 83 remaining after patching.
7HIGH12MEDIUM71LOW1UNKNOWN
Awaiting upstream fix
No fix is available yet for these vulnerabilities.
| ID | Package | Installed | Fixed | Severity |
|---|---|---|---|---|
| CVE-2026-29111 | libsystemd0 | 257.9-1~deb13u1 | HIGH | |
| CVE-2025-69720 | libtinfo6 | 6.5+20250216-2 | HIGH | |
| CVE-2026-29111 | libudev1 | 257.9-1~deb13u1 | HIGH | |
| CVE-2025-69720 | ncurses-base | 6.5+20250216-2 | HIGH | |
| CVE-2025-69720 | ncurses-bin | 6.5+20250216-2 | HIGH | |
| CVE-2026-4437 | libc-bin | 2.41-12+deb13u2 | MEDIUM | |
| CVE-2026-4438 | libc-bin | 2.41-12+deb13u2 | MEDIUM | |
| CVE-2026-4437 | libc6 | 2.41-12+deb13u2 | MEDIUM | |
| CVE-2026-4438 | libc6 | 2.41-12+deb13u2 | MEDIUM | |
| CVE-2026-4105 | libsystemd0 | 257.9-1~deb13u1 | MEDIUM | |
| CVE-2026-4105 | libudev1 | 257.9-1~deb13u1 | MEDIUM | |
| CVE-2026-27171 | zlib1g | 1:1.3.dfsg+really1.3.1-1+b1 | MEDIUM | |
| CVE-2011-3374 | apt | 3.0.3 | LOW | |
| TEMP-0841856-B18BAF | bash | 5.2.37-2+b7 | LOW | |
| CVE-2022-0563 | bsdutils | 1:2.41-5 | LOW | |
| CVE-2025-14104 | bsdutils | 1:2.41-5 | LOW | |
| CVE-2026-3184 | bsdutils | 1:2.41-5 | LOW | |
| CVE-2017-18018 | coreutils | 9.7-3 | LOW | |
| CVE-2025-5278 | coreutils | 9.7-3 | LOW | |
| CVE-2011-3374 | libapt-pkg7.0 | 3.0.3 | LOW | |
| CVE-2022-0563 | libblkid1 | 2.41-5 | LOW | |
| CVE-2025-14104 | libblkid1 | 2.41-5 | LOW | |
| CVE-2026-3184 | libblkid1 | 2.41-5 | LOW | |
| CVE-2010-4756 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2018-20796 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010022 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010023 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010024 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010025 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2019-9192 | libc-bin | 2.41-12+deb13u2 | LOW | |
| CVE-2010-4756 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2018-20796 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010022 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010023 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010024 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2019-1010025 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2019-9192 | libc6 | 2.41-12+deb13u2 | LOW | |
| CVE-2022-0563 | liblastlog2-2 | 2.41-5 | LOW | |
| CVE-2025-14104 | liblastlog2-2 | 2.41-5 | LOW | |
| CVE-2026-3184 | liblastlog2-2 | 2.41-5 | LOW | |
| CVE-2022-0563 | libmount1 | 2.41-5 | LOW | |
| CVE-2025-14104 | libmount1 | 2.41-5 | LOW | |
| CVE-2026-3184 | libmount1 | 2.41-5 | LOW | |
| CVE-2022-0563 | libsmartcols1 | 2.41-5 | LOW | |
| CVE-2025-14104 | libsmartcols1 | 2.41-5 | LOW | |
| CVE-2026-3184 | libsmartcols1 | 2.41-5 | LOW | |
| CVE-2021-45346 | libsqlite3-0 | 3.46.1-7+deb13u1 | LOW | |
| CVE-2025-70873 | libsqlite3-0 | 3.46.1-7+deb13u1 | LOW | |
| CVE-2026-2673 | libssl3t64 | 3.5.4-1~deb13u2 | LOW | |
| CVE-2013-4392 | libsystemd0 | 257.9-1~deb13u1 | LOW | |
| CVE-2023-31437 | libsystemd0 | 257.9-1~deb13u1 | LOW | |
| CVE-2023-31438 | libsystemd0 | 257.9-1~deb13u1 | LOW | |
| CVE-2023-31439 | libsystemd0 | 257.9-1~deb13u1 | LOW | |
| CVE-2025-6141 | libtinfo6 | 6.5+20250216-2 | LOW | |
| CVE-2013-4392 | libudev1 | 257.9-1~deb13u1 | LOW | |
| CVE-2023-31437 | libudev1 | 257.9-1~deb13u1 | LOW | |
| CVE-2023-31438 | libudev1 | 257.9-1~deb13u1 | LOW | |
| CVE-2023-31439 | libudev1 | 257.9-1~deb13u1 | LOW | |
| CVE-2022-0563 | libuuid1 | 2.41-5 | LOW | |
| CVE-2025-14104 | libuuid1 | 2.41-5 | LOW | |
| CVE-2026-3184 | libuuid1 | 2.41-5 | LOW | |
| CVE-2022-0563 | login | 1:4.16.0-2+really2.41-5 | LOW | |
| CVE-2025-14104 | login | 1:4.16.0-2+really2.41-5 | LOW | |
| CVE-2026-3184 | login | 1:4.16.0-2+really2.41-5 | LOW | |
| CVE-2007-5686 | login.defs | 1:4.17.4-2 | LOW | |
| CVE-2024-56433 | login.defs | 1:4.17.4-2 | LOW | |
| TEMP-0628843-DBAD28 | login.defs | 1:4.17.4-2 | LOW | |
| CVE-2022-0563 | mount | 2.41-5 | LOW | |
| CVE-2025-14104 | mount | 2.41-5 | LOW | |
| CVE-2026-3184 | mount | 2.41-5 | LOW | |
| CVE-2025-6141 | ncurses-base | 6.5+20250216-2 | LOW | |
| CVE-2025-6141 | ncurses-bin | 6.5+20250216-2 | LOW | |
| CVE-2026-2673 | openssl-provider-legacy | 3.5.4-1~deb13u2 | LOW | |
| CVE-2007-5686 | passwd | 1:4.17.4-2 | LOW | |
| CVE-2024-56433 | passwd | 1:4.17.4-2 | LOW | |
| TEMP-0628843-DBAD28 | passwd | 1:4.17.4-2 | LOW | |
| CVE-2011-4116 | perl-base | 5.40.1-6 | LOW | |
| TEMP-0517018-A83CE6 | sysvinit-utils | 3.14-4 | LOW | |
| CVE-2005-2541 | tar | 1.35+dfsg-3.1 | LOW | |
| TEMP-0290435-0B57B5 | tar | 1.35+dfsg-3.1 | LOW | |
| CVE-2022-0563 | util-linux | 2.41-5 | LOW | |
| CVE-2025-14104 | util-linux | 2.41-5 | LOW | |
| CVE-2026-3184 | util-linux | 2.41-5 | LOW |
Source
Copa (in-place patch)
Platforms
linux/amd64, linux/arm64
Registry
ghcr.io/verity-org
Upstream
mirror.gcr.io/library/redis