Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

37.0-debian-fips-dev, 37.0-debian13-fips-dev, 37.0-fips-dev, 37.0.0-debian-fips-dev, 37.0.0-debian13-fips-dev, 37.0.0-fips-dev

Index digest:

sha256:6e6b47599a13f134021462e013e9378013dbc378247f7c0fc304df688249eb8a

Manifest digest:

sha256:52ec70117aa53ebda6e017c650c26482c76426bb48b76938345f5b3f2623baff

Size

1.10 GB

Last pushed

22 hours ago

Vulnerabilities

3
27
32
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:43ac4b800c8328845ebf1e12028a30dee769843ce0a4866a52510c820c6c3b96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:6ed533943fe3251143aea105afa4a68bb3268673cdf9d355a0dfaa597dfe8b17
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:e4cf93ee230e867f6ea94531450e36c57e00dd11fa7cbc6eb9a590e8de24e05a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:3c1ad8cbe213eb91dddc8bc7fe666d9068f4df3f8bb16e0b9ff2f1dc8da13376
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:c421fa7373cb729a140943e51f1c9a985f9faa2d2ed244fe4f59bed84f3abb5c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:cc49f0a2a1e063fd7e029fd729fd9b155d0130332b58147aea68f810b6b57de3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:b8e884790b6d27ef4e7977babc4660fd24b781eb3199f18ed7a5dfb51f555ff7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:131e3e8d82905d60e7ecffc246fed842fdbbe2cc466dcf0a44c75a4fa6153d44
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:07fb726d5510e10e7735d3719bd2efe7f839587f8417931c183a68b548d5a138
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:2d16a85f20dcf9b37a7545d6978a9e479759ae92f5d00d463a13be522e5ecf52
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:183bee59bb34633df4db61c5c0b241cd1ce13c8312665cb82296814518eb0b1d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:7279b4918f4c9db1c1dc1ad138992e5d9ccc381329b91b731c715b1f4926565d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:cf8e30d15efbabad6082c1a5c4548b10437dd2fda9457c41451718da1395d8f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:9148dbf444a414abcafd37bee389f774a4eaf1219ab6e1fa315e5c17066fd1d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:2f5ea0665f08ba8f9f893886fa87536f4c5b6297020276b6e0ab41042b32899b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:f06a837f10b4529b4b0f38aa089c977b2afcbe4cba9d4eca223ff3f924cb9c9a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:8345c76c5e03089d32ebb6ab6e8aec35481efa88e9244b8fb681fd37861952f2