Bind9 9.20
hardened
latest
Size Reduction
-123%
41.8 MB to 93.3 MB (-51.5 MB saved)
Component Reduction
7%
44 to 41 packages (3 removed)
Vulnerability Reduction
0%
0 to 3 vulnerabilities (-3 eliminated)
Image Comparison
| Property | upstream | hardened |
|---|---|---|
| Image | docker.io/internetsystemsconsortium/bind9:9.18 | ghcr.io/armorred/bind9:9.18.33-hardened |
| Size | 41.8 MB | 93.3 MB |
| Layers | 13 | 43 |
| Components | 44 | 41 |
| Vulnerabilities | 0 | 3 |
| Runtime User | root | 65534 |
Vulnerability Analysis
upstream
0 total
hardened
3 total
Hardened vulnerability details (3)
| CVE ID | Severity | Package | Version | Fixed In |
|---|---|---|---|---|
| OSV-2023-1398 | medium | file | 5.45 | 81a0cbd10c347496bdee7dde78f7e47a16b4e79f |
| OSV-2023-505 | high | file | 5.45 | 1fc9175166fc5c5117838a1dcfb309b7c595eb56 |
| OSV-2021-777 | high | libxml2 | 2.13.8 | unfixed |
Software Bill of Materials
upstream components (44)
- alpine-baselayout 3.7.1-r8
- alpine-baselayout-data 3.7.1-r8
- alpine-keys 2.6-r0
- alpine-release 3.23.2-r0
- apk-tools 3.0.3-r1
- busybox 1.37.0-r30
- busybox-binsh 1.37.0-r30
- ca-certificates-bundle 20251003-r0
- fstrm 0.6.1-r4
- jemalloc 5.3.0-r6
- json-c 0.18-r1
- keyutils-libs 1.6.3-r4
- krb5-conf 1.0-r2
- krb5-libs 1.22.1-r0
- libapk 3.0.3-r1
- libcap2 2.77-r0
- libcom_err 1.47.3-r0
- libcrypto3 3.5.4-r0
- libgcc 15.2.0-r2
- libidn2 2.3.8-r0
- libintl 0.24.1-r1
- libmaxminddb-libs 1.9.1-r0
- libncursesw 6.5_p20251123-r0
- libproc2 4.0.5-r0
- libssl3 3.5.4-r0
- libstdc++ 15.2.0-r2
- libunistring 1.4.1-r0
- libuv 1.51.0-r0
- libverto 0.3.2-r2
- libxml2 2.13.9-r0
- lmdb 0.9.33-r0
- musl 1.2.5-r21
- musl-utils 1.2.5-r21
- ncurses-terminfo-base 6.5_p20251123-r0
- nghttp2-libs 1.68.0-r0
- procps-ng 4.0.5-r0
- protobuf-c 1.5.2-r2
- scanelf 1.3.8-r2
- skalibs-libs 2.14.4.0-r0
- ssl_client 1.37.0-r30
- tzdata 2025c-r0
- utmps-libs 0.1.3.1-r0
- xz-libs 5.8.2-r0
- zlib 1.3.1-r2
hardened components (41)
- acl 2.3.2
- attr 2.5.2
- bash 5.2p37
- bind-hardened 9.18.33
- c-ares 1.27.0
- coreutils 9.5
- file 5.45
- file 5.45
- gcc 13.3.0
- gcc 13.3.0
- glibc 2.40-66
- gmp-with-cxx 6.3.0
- jemalloc 5.3.0
- keyutils 1.6.3
- krb5 1.21.3
- krb5 1.21.3
- krb5 1.21.3
- libcap 2.70
- libcap 2.70
- libcap 2.70
- libedit 20240808-3.1
- libev 4.33
- libidn2 2.3.7
- libidn2 2.3.7
- libidn2 2.3.7
- libunistring 1.2
- libuv 1.48.0
- libuv 1.48.0
- libxcrypt 4.4.36
- libxml2 2.13.8
- libxml2 2.13.8
- libxml2 2.13.8
- ncurses 6.4.20221231
- nghttp2 1.64.0
- nghttp2 1.64.0
- nghttp2 1.64.0
- openssl 3.3.3
- openssl 3.3.3
- openssl 3.3.3
- xgcc 13.3.0
- zlib 1.3.1
Download SBOMs
Usage
$
podman pull ghcr.io/armorred/bind9:9.20
Verify Signature
$
cosign verify --key https://armorred.org/cosign.pub ghcr.io/armorred/bind9:9.20