Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x

CIS
linux/amd64
debian 13
Tags:

37.0, 37.0-debian, 37.0-debian13, 37.0.0, 37.0.0-debian, 37.0.0-debian13

Index digest:

sha256:ae73524a42771e05a4b7644ebb711ae88dc9697cf9580c877c15c9c4a2f72442

Manifest digest:

sha256:ae7141f7a7872bfce712ced3ce034d2d336bf0c5bca0075f7f2b392afda0a42e

Size

1016.88 MB

Last pushed

10 hours ago

Vulnerabilities

3
22
31
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:09db70f7aa0f942704d9f7d1c9c7bd566d25c43f481cfe67a824db3aad4025d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:0c6246800b4ae411c9c45c71734c6a4a95ab05ead7f9a53fe8ddd57f4af624ce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:c0a2a1953422860b3ed9ea3bcfa87e0c1f0a2d988f1f6dbfbe4a8d7ea0403617
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:33da522dfa3e1efcf688b2fae1604b643f80da979548d5d34b50cdaa6e203433
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:abd98edc807ab0078d2ea9bd6754366da89825c81c537da5b472bafe5fe7ed2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:03b99346deb36f610ae593ded5334ef5b356385baaca0cd282180c6825644612
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:4d7da6aba2bfe9c4aac9190419ebd1df8a360047e1eeb74dda551ad4a4941fe3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:99b8971b6c1272593c230e6dbf7a996ed56a62e7dee3e452248b3fda1b591fa7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:c64afd5bd0f352831d82c9cf09caa5216cd9c857e2424886f0105175f45da7e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:e898f998dc3ba255e86beda3eb3f65ca8c3c51e50067f7ae72bc0cfa2821cbea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:6ee383eca24ac5a8ad500079206b7c7c589a3b9e7e1b0ec4b2bf0391e335aea1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:7d36d678248b6136ecade7b9576c8dc06ab182621eeeab299dc47c61e46bf5f2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:a4e818eccace3a94bedb1ff7a97b7a7b5abac8bf4873f68f56744bea8bd30b90
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:fe813c9659d3119b69c5d6b804cd7ed365fe1bc30548520f8d44ca390eb40d9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:37dc16d0582fcedef1bb919bc4e8b73101affe6579178eda9fb140f4aefb6985