Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x

CIS
linux/amd64
debian 13
Tags:

9, 9-debian, 9-debian13, 9.10, 9.10-debian, 9.10-debian13, 9.10.1, 9.10.1-debian, 9.10.1-debian13

Index digest:

sha256:695f5c9ac8db1e6ee6f85ca882dd889d7e6081812255e7a3398a66e267b2fd3c

Manifest digest:

sha256:2e3c88de7a016f79077609453c2479f31e52a8bf4efb4908c6ac7158630b8e0b

Size

114.07 MB

Last pushed

1 day ago

Vulnerabilities

0
10
2
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:90912ae165f3b9f804ed20c250fb65fd353e1635b53f448d3bc77ea72db84496
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:416f1bb56bc712a2368e08c10d2abd4906a3a41f129291f000e2b98e866e5be2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:657ed450133d09a039d8b139adfebb82ffc2343de324abeaf13b0c5e426dd529
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:a2a16f59aa3973f6fd56a2bdaa96acd3d68decec0aa70441c47cb8163b116786
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:a772ac27c0ed50101b033a08d3669ca2ee5475bef9af034f1b0285dd6fb8f63a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:69136da430a956db9a7e978f56d0e8c75ee6a6eb7163991669cd7085811bdac2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:4173f86cbc6439170fab6435f90f02617016371615642beba7596ea0cd5a4cc7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:7202be0787b5e57b4232619277ae44893b46840c8228a1d990534823e6ce0d78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:e1410fc6dd7af2d3c671b80fe69c04a5117e143506c038b20cea41782c981ae3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:15bed0a5ba2e4ae6c824f0565c993449431aaa6ae263d51909904c49e88c855e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:7bedb04fd0340d8b476a9fc6929958ae68e162923aaf0e161a7c70a4d3e2f300
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:ba4adc58c8525562f6cf3e162871d3b73d4ab18e78091c860ba987624f11cfc5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:51d5faa8ef6c997bd85c5ce1f1034d2849748b6b3194aea73755b39b3a86b174
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:09406ac8ed1a6716421dc9450763007a742d6d449809df5b17467247a9c64ae6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:8bfff7f75f708ab85d52a5fb0313419d41d530a19447b6de1203d5da7ffd7dda