Sign inSign up

readystack/mysql

By readystack

•Updated about 19 hours ago

Image
0

363

readystack/mysql repository overview

⁠MySQL Community Server

Docker Scout: Grade A Fixable Critical/High CVEs: 0 Signed: cosign

readystack/mysql:9.7.2-CE-ubuntu24.04-r1

A hardened, cosign-signed, offline-rebuildable build of github.com/mysql/mysql-server tag mysql-9.7.2 (MySQL 9.7.2, a release of the 9.7 LTS series; GPL-2.0 with Oracle's additional permissions, see the LICENSE file at that tag), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout Grade A — 0 fixable Critical/High, non-root, SBOM + provenance attestations; re-checked daily at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/mysql:9.7.2-CE-ubuntu24.04-r1.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is 9.7.2-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/mysql:9.7.2-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/mysql:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/mysql:9.7.2-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container. MySQL Community Server 9.7.2 (9.7 LTS) compiled from the upstream source tag with CMake and installed in /usr/local/mysql. The image is the whole database server: there is no external database and no sidecar. mysqld runs in the foreground as the non-root mysql user. On the first start with an empty data directory the entrypoint creates the data directory in /var/lib/mysql and sets the root password before the server opens a network port.

docker run -d --name mysql -e MYSQL_ROOT_PASSWORD=YOUR_ROOT_PASSWORD -p 3306:3306 -p 33060:33060 -v mysql-data:/var/lib/mysql readystack/mysql:9.7.2-CE-ubuntu24.04-r1

Replace YOUR_ROOT_PASSWORD with a password of at least 8 characters, in single quotes (-e MYSQL_ROOT_PASSWORD='...') when it contains spaces or characters such as $ or !, which the shell would otherwise split or change. On an empty data directory the image refuses to start without one, and refuses the placeholder itself.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:97d0863fa…

Size

155.8 MB

Last updated

about 19 hours ago

docker pull readystack/mysql:9.7.2-CE-ubuntu24.04-r1