Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x

CIS
linux/amd64
debian 13
Tags:

37.0, 37.0-debian, 37.0-debian13, 37.0.0, 37.0.0-debian, 37.0.0-debian13

Index digest:

sha256:54c985b946a7ba363126df4a66c3b3c8a06fd500d7068c5290b25c26de7f1bf0

Manifest digest:

sha256:531cf8b7575d5fdb9605a1baab51096bc332a5b84498a54cb44f989268aa8065

Size

1015.65 MB

Last pushed

53 minutes ago

Vulnerabilities

3
21
27
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:897404ec17ec0419b1e19abc944d4fedfbc8528be7533595b992b0cce2c32422
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:7806edf90c79ba006bb56cd7a4c8d56b665dde3a1d5857d7fb37f520f32509ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:8eb977fb1a37b682ee3f9b8f8f7c29a28a109edab70dc8405d8254481be26b48
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:9f39dfaf2258994ea7fb1873fb100e099705f23196251b31abc208414abaa4a1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:15b7aa6e1cc1ed19410f4cec039434764e176b41e968be04e199a4491ec31335
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:724a4da31ed2a344a2be90eb2b3574ec27da004cb66b5d6f5a939379dbbdddfe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:ed0af3c29792ed3716ee442e4cd37cbba5d21d5e474cfccead95277628c4006a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:cf999e4259b9eb4aaa9af97a7258db835099a2795bbdee518f171de989fc218f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:b61600ddfa448d8d7e7bdcdcf8ac80eae519185c8004095f6aa710c8ab5ed231
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:64b17caf0bb0bd7a01878e7a913ec7ad7cb60e21060ba08e135a2943e5909886
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:9c7a57015c46a30faf1dc4c059157ea3c29f1d174dc21f1830b7670a4a913209
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:f1820866a57fc2939952c6cd23144270c02ca040323082662040e9bd80aa2aa1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:b40dfd74a47302850d431870bd8b3cf340ee6e4554c40e18194f3a3ced2d48a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:304d2eb40124b833bc070e717362547b1cc0fd8e52065f5bc9c7821059bac544
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:8fc807c397e2a6c0ca9ad92907635ca216966beeb874338a3f612204ccf2acf6