Sign inSign up

tychoncorp/ubi9-stig

By tychoncorp

•Updated about 1 month ago

STIG-hardened, fully-patched Red Hat UBI 9 base. 0 fixable CVEs, 228/228 container STIG.

Image
Operating systems
0

208

tychoncorp/ubi9-stig repository overview

⁠STIG-hardened Red Hat UBI 9 — tychoncorp/ubi9-stig

A minimal, DISA STIG–hardened and fully-patched Red Hat UBI 9 base image, built and verified by Tychon's automated hardening framework.

⁠What's inside

  • Base: registry.access.redhat.com/ubi9/ubi (:latest — always the newest published base)
  • Hardening: DISA RHEL 9 STIG applied via reappliable remediations — pwquality, PAM/faillock, the full DISA auditd rule set, login.defs, sysctl, DoD banner, kernel-module blacklists, sudo/su, fapolicyd deny-all, and more.
  • Fully patched: every build runs a complete dnf upgrade of the base before hardening → 0 fixable OS-package CVEs (per the vendor's authoritative errata feed).
  • Self-describing: the STIG benchmark + container tailoring are staged at /usr/share/tychon/stig/, so the image can be re-scanned with no external content.

⁠Compliance

  • 228 / 228 of the in-scope, container-tailored DISA RHEL 9 STIG rules pass. Excluded rules are architecturally not-applicable to a container (bootloader, systemd-as-PID-1, physical console, separate partitions, …) — each with a recorded rationale.
  • 0 fixable OS CVEs at build time.

⁠Tags

  • latest — most recent build
  • YYYY-MM-DD — immutable dated builds

⁠Usage

docker pull tychoncorp/ubi9-stig:latest
# the benchmark travels with the image — re-scan any time:
docker run --rm tychoncorp/ubi9-stig:latest ls /usr/share/tychon/stig

⁠Currency

Rebuilt on the latest base with a full patch on a schedule, so :latest stays current and CVE-free.

Hardened by Tychon.

Tag summary

Content type

Image

Digest

sha256:a3c606ee3…

Size

117.1 MB

Last updated

about 1 month ago

docker pull tychoncorp/ubi9-stig