Sign inSign up
SonarQube

dhi.io/sonarqube

SonarQube 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.9-debian-dev, 26.9-debian13-dev, 26.9-dev, 26.9.0-debian-dev, 26.9.0-debian13-dev, 26.9.0-dev

Index digest:

sha256:97d80f830512ec6820ba43ff5b1c5c2f858a4125d517ebf40e2513690163a923

Manifest digest:

sha256:924a7e0c3e6109c526f542980693d42583a6a5b6b1157eebca79df0a399a11e3

Size

1.02 GB

Last pushed

17 hours ago

Vulnerabilities

0
0
5
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sonarqube:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sonarqube:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sonarqube@sha256:64cfcb1056cd1c73dc7e6e9b54093059086d7f9328636425dcc7065cae5c86f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sonarqube@sha256:7db899a62b1a92f62519bc437c6b3891c90b5cd439698aaab2d4376804b4a613
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sonarqube@sha256:5479a121ba36305cacb08d5ca4f8b83dc017c3d8376f4a99ede19f3a3401a7f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sonarqube@sha256:d4b23d16d6285727add0bd5867ce5cd9c173706276ded57a9cdfa3910d61c8a0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sonarqube@sha256:15bdf020c58baf827864b65f9ecef010afd4026184fc029a338e1b5b9991465f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sonarqube@sha256:26e9013cdfebf408ffcfa55819d456e33c28f1921d2592720d54730546b81101
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sonarqube@sha256:47746a3dc4625275d3f28baf5f7d58a2b7f32fca290cebd58caeeb41e634739a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sonarqube@sha256:105bf1fca53cad41cdfa7a734c509d976155ffc12e9d951744076d55009762c6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sonarqube@sha256:eb68c5566400fc2ff61d685728dfab982a2771173ba2cf81d29d8293eac3e4ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sonarqube@sha256:b7935c1935142f333e7067ac08689c9482b35441558e0bbcc3e4a896152c673c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sonarqube@sha256:90da5f53acfac8a6e85ee2a82969bf1eb8044924e78a67fc69f24d21af06f88d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sonarqube@sha256:aa9771897b951dcb429be12c24e85464962276c1b1fa49174395a565c52c0645
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sonarqube@sha256:f948443896dd52fbdfd224f2a72b6b88c62c6ebdb5dc877ea2536d7e6493a503
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sonarqube@sha256:4f732af09fa75385079dc69982e7ed0a09952de6ceee48a38451b09af22b772e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sonarqube@sha256:89d0f8cbd20446ba168b19f1823f2607b75fe0feb9098c0a366a90ff73c942d1