Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (dev)

CIS
linux/amd64
debian 13
Tags:

36-debian-dev, 36-debian13-dev, 36-dev, 36.0-debian-dev, 36.0-debian13-dev, 36.0-dev, 36.0.0-debian-dev, 36.0.0-debian13-dev, 36.0.0-dev

Index digest:

sha256:1a9987d45a6fc3dfc6263ce75f02830c0433ebf4cb736eb655093dacfc61a2f6

Manifest digest:

sha256:ec6676d3de586ae4c8ed9980706967760b31908b2db01c57f472b37157d5078a

Size

1.08 GB

Last pushed

10 hours ago

Vulnerabilities

4
33
42
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:e6b8f4d70715a21f63fdc6bbf96f58cb41fd266034795db703462a6ce6ad812c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:c5f71b8faa7d80aa83ef727ab6e17ebdb65075daf05697ef59459d0186075c88
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:dd18057d9063d0496fe36adb61cb0fbfe79461c575c16e08f9677c0b03ec3533
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:83f6bea14e7d1b0685b3ca0335c0a5d3355015629cb7f2fe2cce0889016ed98e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:606f6e0be68de3399e070c3130a10c9ce8041bdd73c2a9c823c62803f87f9d5d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:2ebfd3e6a124a4cc8f00d4aa20a6abf94c558fc9e9ca2a517937be0f73fa7fa8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:02e8d94009d1f919e4ab4815db8a1b961641ebf56284431b214bd5f1578ab5e1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:d6d28aa339688f40233c78934d8a01bdd981a2d8c15490871aee9516113cd276
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:c6357d09fbadffe842451a2cddb2c5a0b621849684bf775ca575f72e26d60572
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:9d1034bdb91eaac388ace83346d4941bb42c33979a569908d00fcf8d05e81344
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:dd78b535643dc857a156d99281819cd9f9a1d20868b70765d11706786c9e48c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:7af56ff05622ffe09b717deae1b1a5d442646424868392b0c21898d7b773c7cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:009382bc18d6ceddbb4642f4369ff5d63362e0d70f75a3200510d7961ff41287
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:5b7414773024566f64fc94067dfb105a8523ccbf716a74a985e0b303dec7ac69
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:4e5f264f4d68135191139c00dbc6e0ccec2e53698357c00ecfb20c61741dddfa