STIG-hardened, fully-patched Red Hat UBI 9 base. 0 fixable CVEs, 228/228 container STIG.
208
tychoncorp/ubi9-stigA minimal, DISA STIG–hardened and fully-patched Red Hat UBI 9 base image, built and verified by Tychon's automated hardening framework.
registry.access.redhat.com/ubi9/ubi (:latest — always the newest published base)login.defs, sysctl, DoD banner, kernel-module blacklists, sudo/su, fapolicyd deny-all, and more.dnf upgrade of the base before hardening → 0 fixable OS-package CVEs (per the vendor's authoritative errata feed)./usr/share/tychon/stig/, so the image can be re-scanned with no external content.latest — most recent buildYYYY-MM-DD — immutable dated buildsdocker pull tychoncorp/ubi9-stig:latest
# the benchmark travels with the image — re-scan any time:
docker run --rm tychoncorp/ubi9-stig:latest ls /usr/share/tychon/stig
Rebuilt on the latest base with a full patch on a schedule, so :latest stays current and CVE-free.
Hardened by Tychon.
Content type
Image
Digest
sha256:a3c606ee3…
Size
117.1 MB
Last updated
about 1 month ago
docker pull tychoncorp/ubi9-stig