Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (dev)

CIS
linux/amd64
debian 13
Tags:

37.0-debian-dev, 37.0-debian13-dev, 37.0-dev, 37.0.0-debian-dev, 37.0.0-debian13-dev, 37.0.0-dev

Index digest:

sha256:6458600ee093f90a64b78c55b6fff7cb1c97e3a27dfbea98e81cdc21235aae7f

Manifest digest:

sha256:8196cb836658181cacd697b5ab189218d5f6fc2587c1c6f5c90c9cebea335edc

Size

1.09 GB

Last pushed

10 hours ago

Vulnerabilities

3
28
38
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:ff61f078dc9876bfec51aea4e9417adf7e865d7cf8c5226fdd184b958ccbec87
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:7307651a1f92c35bb829bbdd7f4daadb26f110000f05b21fcff6f1900b3872f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:f68f6eceaaa303fbc8979ffc52b5ff948fd706197afa4662ca8ff5f7ba3d0343
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:1a4f73910bae12682a11aa08f89fe65bf114d33f4e87bf1756d038012226aeb0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:41880249054d213e5ca757d5a70978c7967ec30527086f2d49e3aa6721e53ba2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:c5fb3eec510a06b604d073485b4ec533ab2cd8968e88220a508cdc3b11df8229
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:946f81293a262b15336a2eea5d72ec412a446bef5c20623bf05292ca921347ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:5a98ce5485e0a56c9a84416afe08c62d86b908948f681e7a50ebb211314e06d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:8178dff7caaf5de31f7f27b2a0f8cc3eb77a0de70660dce7026ed733f1b6724c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:ec61a6d902592a574a4ef0fb54d43ec25a5ffb08de3e1760f3a344eddb3a00e5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:1fcf124c62b417e1748e9ecbd8da805bb01d12c10be4cd8cbc8fda83bcb34f45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:425d3467e33353511f5c89d268f46976e2007247bc3306c6ff6ba28c6fa12f6c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:0cf4462b4a9d8f370061f0f7ab0e9bf38a8648f0925deac823c30c1de58868db
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:1cf5fc2c92b6d86d28110ac974d4dd224a293a7c05a5f1a235084d1fbc11c2d8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:2e7827689b6d8c1a707a3c119671adb5aba0b1b13c6680713eecf89319de00f7