Sign inSign up
Cassandra

dhi.io/cassandra

Cassandra 4.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4.0-debian-fips, 4.0-debian13-fips, 4.0-fips, 4.0.21-debian-fips, 4.0.21-debian13-fips, 4.0.21-fips

Index digest:

sha256:a891c031cc977d8f32e6bd434d92bf25024c9746ef0b23402d8bea97c41ed254

Manifest digest:

sha256:a67210e8c1bd089a9b22e8b4a085ddceda85e8d9ad50b08b2bc6d98d106b670d

Size

128.22 MB

Last pushed

2 days ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cassandra:4.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cassandra:4.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cassandra@sha256:dc2823b1e5c28956ab00ae4b0945471a8be88bb05fa8d44b69d22a727ad9c88f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cassandra@sha256:31763017c243d0a89d9c9e05d829ed19161298590dd4d8fa52f67dce23b29635
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cassandra@sha256:ddb6ac99dcb8b51439798da2ad43ecd810bec65ea3912865eccec29e8d6e6a25
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cassandra@sha256:55ae8d3a8435085e510a66e6f43a1f44c77542453e1c58d7d0c8ac4773813911
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cassandra@sha256:411368a0cf8cbcbd7e67492f137346b8801b271973881f9c874cbdebb6c6e895
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cassandra@sha256:b607b4ddca68ac1fc188065a96cceb65d372bdf0c8d01aae095042f517822607
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cassandra@sha256:0fb78fd8e372c466e16623e60e3a5dacbe4212c83d59fb3a222ff4fd85d61f8b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cassandra@sha256:fbdc20ba35b4fd976ac21b8a51924d39e3b8d55e70cd4766b1db44215fe787ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cassandra@sha256:13d8562b771513c6049aa83a07865c3f46d1b5771a1f557a3b5defc53f9de518
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cassandra@sha256:a573cde7f1c83fa3248cbe2b903dba2383cf1a2e399a30c4af2a975b26a9dc42
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cassandra@sha256:54de3ea3667f4daa933deffdd144bb17835b381c3b3d02590174e4766e0ab6df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cassandra@sha256:f085bef1ed13ca5d40db567182d9be8d27732cdbde3e9b453196de147f79090f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cassandra@sha256:2dc2296b7c8f3dfd7d787342916a25c47fe9bd9b6031b63c6b689e2ba512d257
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cassandra@sha256:34b09d2109a4f441518150caab313ba67a8750214a8ca872d9c017fea152d4b5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cassandra@sha256:e4df28a2a3f7fb5c12e0572cc0a1e7b2f7da1010575fa05a8e768686b32e254b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cassandra@sha256:79c89d348c88a057ed3211b7af49fa18b2a985b621ec2d0ef4688a97cae2da95
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cassandra@sha256:6120e0b5e72a40d5f7eb5775e81b9b93f7701bd0cb18417d307d5aedf5e62f70