dhi.io/druid
36-debian-fips-dev, 36-debian13-fips-dev, 36-fips-dev, 36.0-debian-fips-dev, 36.0-debian13-fips-dev, 36.0-fips-dev, 36.0.0-debian-fips-dev, 36.0.0-debian13-fips-dev, 36.0.0-fips-dev
sha256:3a62ea3bb36d0b9107448180a98ba215d04942a491da599806a770d4b2a7bac6
Manifest digest:sha256:9fc9cc3a1ff0d2544f2e9044d86f03cbab9517f1965979926b355785f3c6aa86
Size
1.09 GB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/druid:36-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/druid:36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/druid@sha256:a1c01eb68e514cedcd4cde76670528002a5d07fc5e4daa3ae3dd1737c8e277da |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/druid@sha256:91d2932d89ee1545364d2e6862a836c5d523469c465db07b393f15fcedb0b3fd |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/druid@sha256:f2a72f62e1653c063c0bac444546b561831cac9cb145912691ae6d035129e179 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/druid@sha256:a6823cdf32e71a0de58b8125079a0c4e30a4430298007a98de9f1c4384b21b1c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/druid@sha256:b22a53b486b7a417a126561e5feee83540c59ac0cd496833bcb96010bf61e0d7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/druid@sha256:c038373a6e3604fee412ab0fc535cc4cee985e5ec81f36fcdc1c26857121417f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/druid@sha256:3a75f641aaad1b514bb0f0d7f4fe8b2b4a129d3902cd3754fe98cabc44a81932 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/druid@sha256:b4127bd74c78ccca2613028da6d249b7ad7d397155dcc6a5a589a9274ae56d65 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/druid@sha256:486395fdd2d9c12844488e627dbfc2e8bb6cad2715019cb9ae6121c2ceed26ed |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/druid@sha256:1403fb2943cd029ddf9090be69487faf99552d82ea5724346da43b1da93b2a4c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/druid@sha256:75b1df38fcda6daeca40ebb5638b53f21059a6761f2a51c940e272ca7a0b136c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/druid@sha256:abb2058c0087af51c9c771a46a3c16bd050eadb9d226ab1edc575a93712b18b0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/druid@sha256:c7047571754f82ff47f728c0dcdaec437a392ffa28aa323ee856a06364660a86 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/druid@sha256:29d1bca7e5c4420caa1041db2303b73529f6b735c482e53dafb41b3b4e746c65 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/druid@sha256:7a187e327020a27d72375a0cde542d68b4dc461d10a480cdd98de10a4f9f1ea7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/druid@sha256:61256dba320fdda91c52c787581af83f0ac7033960dbeea820a2fd61db05a259 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/druid@sha256:7efcfba85d3fc83c9144b7c0fa7dc00a5c15cb1bb5c7601373b1fe77f30ef0b4 |