Sign inSign up
SonarQube

dhi.io/sonarqube

SonarQube 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.9-debian-dev, 26.9-debian13-dev, 26.9-dev, 26.9.0-debian-dev, 26.9.0-debian13-dev, 26.9.0-dev

Index digest:

sha256:9611a77b9872866c2a9a1be0a2ea10d6f07bcf401a4ea429bcc27eb5fe2b6e30

Manifest digest:

sha256:350d0500cc914e340973e55ca8e3843ffa3715ed10a3f07e85940f7371788c20

Size

1.01 GB

Last pushed

2 hours ago

Vulnerabilities

0
0
2
4
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sonarqube:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sonarqube:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sonarqube@sha256:2fb047b0819d1786a29987f57f7423a226203fbd887f9c2d095c18bd57cc544c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sonarqube@sha256:9053037245a9834e4388f114048a7a8ec4a133b47c52a4182c3f018fd384fa5d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sonarqube@sha256:e5627a724b3eecb7599b3576e486359fd7fad6ae09b07a887180ff2d67384c0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sonarqube@sha256:a6132d6443ae8d4602c5e5402f0b35e720598eac9aea466f694e8ac3339d4e15
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sonarqube@sha256:6621ef26a988d996925c75432456a7ec4fbc561c34ef8ce13fd659276f1ee7b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sonarqube@sha256:103e799c6d1195cc326dce1ef5bede0b7d122466b7b564694052bd15ba8abb73
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sonarqube@sha256:6152406483c13515fd34260e05028090328ceaff680429f0ff968dd5908c8c91
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sonarqube@sha256:e615d3c2f13a895a4329880a7e52a3231969c6fa3727340aa9c42f366bbd3129
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sonarqube@sha256:e03a4b2443b53dfa4f8b28adbae3d88104f1fc5a3366ed054de7e34320bdc5fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sonarqube@sha256:2fb6732f2bc52f8489f56762b04f86286a2407cfaa365336d735fdf7e4b4d4ac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sonarqube@sha256:e0746ec0f99b08d6beda982ea05f6318237ad89c0c0d56c3429fafeb7fa4ef85
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sonarqube@sha256:5095632e170e3a950461f0fbbda3bc0adec799cc52c736dd359e41d836c513b8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sonarqube@sha256:2e7c2773109984282a90f53a0012b3ec9985fe2604e52ce4f203295398313cae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sonarqube@sha256:b52048feb7523db28f4a92f9474c6bdf49da86b0f88f817d3c20313d4bf7da58
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sonarqube@sha256:2b8ed23277058e3e925f592e13f5d98f53d6e1ba44c75d89db47f57727037d83