Sign inSign up
SonarQube

dhi.io/sonarqube

SonarQube 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.9-debian-dev, 26.9-debian13-dev, 26.9-dev, 26.9.0-debian-dev, 26.9.0-debian13-dev, 26.9.0-dev

Index digest:

sha256:9611a77b9872866c2a9a1be0a2ea10d6f07bcf401a4ea429bcc27eb5fe2b6e30

Manifest digest:

sha256:350d0500cc914e340973e55ca8e3843ffa3715ed10a3f07e85940f7371788c20

Size

1.01 GB

Last pushed

5 days ago

Vulnerabilities

1
1
2
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sonarqube:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sonarqube:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sonarqube@sha256:2fb047b0819d1786a29987f57f7423a226203fbd887f9c2d095c18bd57cc544c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sonarqube@sha256:9053037245a9834e4388f114048a7a8ec4a133b47c52a4182c3f018fd384fa5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sonarqube@sha256:e5627a724b3eecb7599b3576e486359fd7fad6ae09b07a887180ff2d67384c0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sonarqube@sha256:8ad0031b3bff17cb57201847c484ea9153d4e0061288ea62b0609463b931ca72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sonarqube@sha256:2eda80c2300c600d76966d8e9c018b641ff62317de543044693201375b93c5f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sonarqube@sha256:103e799c6d1195cc326dce1ef5bede0b7d122466b7b564694052bd15ba8abb73
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sonarqube@sha256:6152406483c13515fd34260e05028090328ceaff680429f0ff968dd5908c8c91
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sonarqube@sha256:e615d3c2f13a895a4329880a7e52a3231969c6fa3727340aa9c42f366bbd3129
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sonarqube@sha256:e03a4b2443b53dfa4f8b28adbae3d88104f1fc5a3366ed054de7e34320bdc5fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sonarqube@sha256:2fb6732f2bc52f8489f56762b04f86286a2407cfaa365336d735fdf7e4b4d4ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sonarqube@sha256:1bb45c1d0914b0a3a0b2e04ce39c15404e427f03df692aa73f32ca895dc90a46
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sonarqube@sha256:5095632e170e3a950461f0fbbda3bc0adec799cc52c736dd359e41d836c513b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sonarqube@sha256:2e7c2773109984282a90f53a0012b3ec9985fe2604e52ce4f203295398313cae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sonarqube@sha256:b52048feb7523db28f4a92f9474c6bdf49da86b0f88f817d3c20313d4bf7da58
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sonarqube@sha256:2b8ed23277058e3e925f592e13f5d98f53d6e1ba44c75d89db47f57727037d83