Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.10-debian-fips-dev, 9.10-debian13-fips-dev, 9.10-fips-dev, 9.10.1-debian-fips-dev, 9.10.1-debian13-fips-dev, 9.10.1-fips-dev

Index digest:

sha256:d074159cdebd16ee609e342ec23ab7dbc06822fee4ea79e31dbcecbfe2f2b6f7

Manifest digest:

sha256:722e818ae2d2b907fce06969e5a4833431ccd8a1045f2af4e606d1ea18f2e763

Size

134.61 MB

Last pushed

58 minutes ago

Vulnerabilities

0
10
2
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:7edd111f2394768816db9b4e4c9f83744f98fb8ebc9c477e2b70ff46c6a40d05
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:a25d89fd7e232ca8e54e384e18e5cf5bccba758f76cc874264e4c4c9d1849578
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/solr@sha256:7be1405295801d710a162e859090812780aad78f373f9863edb5cb832994cad0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:ab8eb4bbe23732341a4cf9152950aca5b3c21d180ed275e32716afe2fc4bed6d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/solr@sha256:0759e93235a1920dc09a6a22f531529267fc8b657ef64533f6a8eab06516a95d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:c11d2e115e2dec4b9fc885924e773ad187af331b308c1dc5007de8137281f5fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:d01eb2ef9f4b9dee37def803252e0db76e0b6772a9d37c177c11c7d2493635e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:6a0a43019abf5e438df9ea500330eb076d38f0b790120a68fc1639be168296a5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:59e467e5b3e42db9d0e653428cd5d0a4ed676a13717faf441bd7c2ae94780ee1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:e3c60ba8d4469c786ab152aa70f4dea36d5614d14f7c68dde7f5056053b945bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:ebf84c998773e66030072a72eef63f835a212ea438e2befbc717fb9df72f039c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:8185180dfe010f43ce41c7fc663aebf67aff62e945f048b555694093539c5539
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:27cca8be3dfab7b61029d32f1edd6723e44f2a6b3492524e807d3d89e5ed1eec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:e0d52028c2bb06cdbef2d30c89071bca350d89014eb33c2097ac18eef990f883
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:123f56667f9806b70d5aa7402eaf18ade00506c9a8ad12d15388ce010cf1357f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:f8690a3b446864e96aabe9f6a4baec912df86669282b0a1bacf4e58a5ddc89a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:a2a85daeb4ae402dbf2f12be4cba7c5c75558e02ab96404f0316f5b299531f65