dhi.io/druid
36-debian-fips-dev, 36-debian13-fips-dev, 36-fips-dev, 36.0-debian-fips-dev, 36.0-debian13-fips-dev, 36.0-fips-dev, 36.0.0-debian-fips-dev, 36.0.0-debian13-fips-dev, 36.0.0-fips-dev
sha256:d7610d299bc95731395be63e7829ac6524a691baaa982a3047d98ee74e7a9c2e
Manifest digest:sha256:f93c9758a62cd7f31c0bf58f6ad5eefea992130c270b2a6c271893ee62f73642
Size
1.09 GB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/druid:36-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/druid:36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/druid@sha256:4dfd0e7ffd812715659f7bb0e3cc893b230fb5bca8c9d7b3da4a7b5befbad4ae |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/druid@sha256:85b0e24feef5b389f0cbc20792e1c9dfb43d2f24f573ddd005ea25d3769d7a0e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/druid@sha256:9eb367ed15dbee3265bd9810200bdccf0e9ae1ebf62570aef9d7abd544c7bab9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/druid@sha256:3027a516e53666dde589c125d3663eeda652c646ddf9d65b66d8b41e2179a02f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/druid@sha256:fe048350690ed6512e8380cb7b785d03651ed9846e6fc5a46b685ab8a702f34c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/druid@sha256:05e3574f59af5c238525d3d2ca647d0872105af23201c80d288f7001540d2fb7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/druid@sha256:5d2a5132ce8138c4e97e25a0e88d0280eac51b1baa0a3fae28080de7ade61480 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/druid@sha256:278b23d97b4d9d409a66ad797cafc6c3b059ed3b5c906184990815baa341fb76 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/druid@sha256:e2abbf49a861ba507790809acebd9578c31a54dd5b2564973e75e2485266415d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/druid@sha256:7545b113e59f56b8e74149f959bbd28d00dc3f52622764a975fb34f8836f56c9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/druid@sha256:2f47e232e9cf89836be1aa4c99849e3dde2814b638285120d2ae10696baa634a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/druid@sha256:4e850c53dffa42310ddccffe5cb5ee99020aff51f72778c2ab7556822622e84a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/druid@sha256:a9a89c271f7ef7f17bef7677c6ae48cdad4aa438417e51fe6f09f9454bedbe3d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/druid@sha256:4feb781cbedbc3fab4f188f8908adf1477d77666428f073b59a8c82d738a5aa6 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/druid@sha256:352396f7ffee357dee44f77cf54f1cf025cf761abb20385d1ab4db2c48c38721 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/druid@sha256:e140dfc1c72ea21822947b7c8bbbcd38a67fb66d0ffba71dd56b7695be7dfe30 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/druid@sha256:61bf607745edbe3941a8eba1764e998b915e59657c93b1f9150c03bb6a189547 |