Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips, 9-debian13-fips, 9-fips, 9.10-debian-fips, 9.10-debian13-fips, 9.10-fips, 9.10.1-debian-fips, 9.10.1-debian13-fips, 9.10.1-fips

Index digest:

sha256:0492911b5a616b9b04ad07526ea0dbe6da50c033e023071c4ee424d94554719d

Manifest digest:

sha256:905fe0b97671e57afb020ec0abb7451c09a1d870ee63e91db5e3107263fe2843

Size

124.53 MB

Last pushed

3 days ago

Vulnerabilities

0
4
2
10
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:52268454d265cd3075d1ebea1be7ba595462a5421f7ea60eacd13fd718a74db9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:92ebd3d2c412dc4834d29bd61482396b8c2100fb63fbb2ba98448008d0a1de41
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/solr@sha256:d3f7d9b7337bc6eea68dde496bc71d7c586cd05695d573147d08a53555a68a1a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:d52075ff51ff03d46f64b30982c9a3f926fc0ede5cdcc395b40d7a87f7b2a97c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/solr@sha256:2bfec6691a8d791a62a6846da4cb1751b9dd112478014ce527fcd1da4cdc2ed0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:6c63eb7573e153cd62f90764ea939c0b0dd041c698598df4a26f8086d05cff8c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:94fb40bdb3551023a6fd9617ef8151d7e6b5a478336f0cd5cbf9dee477d697e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:7693a43f6634af941da0d049e744f3dd2769b0224772f2251b990c1196df47cf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:99742ec2222dfaf2bdc482f7fc5161e4c0305afc47dc8df12122af28ee7aee19
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:102b1773ff495342a9902291c2cffcceada0bdb4815aef923c6e7d8707fe7df7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:5e0d354001614ca0e92dc7c5fc150273d3d03d183924f5f0e40a8535d31b7293
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:4cdc3b899e5d5485e9b9b9b5b9a207fa9ee4b06af811155e0dba7beef23fd851
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:6a010b08a1cbb743789734bc49161fd0e21a35156c27e6095bb50759d241e9af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:3f46b4d061e8adad4460879152730efabb54f7b32747521394a56399e2ad6414
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:c837138672bfaf44eca42823ec4f7330ac6028ef2bb0bd782237178dcae92668
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:d2b4fc2f1842ef4dda7e0e82f254c5e68ceb0d4b0aef976fe6cd04cab9b6d687
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:1e9712fc395b8a8a0b503185719c524795d7da4874832efb5f12c29d80477413