Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (dev)

CIS
linux/amd64
debian 13
Tags:

36-debian-dev, 36-debian13-dev, 36-dev, 36.0-debian-dev, 36.0-debian13-dev, 36.0-dev, 36.0.0-debian-dev, 36.0.0-debian13-dev, 36.0.0-dev

Index digest:

sha256:ac32684afaeb0d50ab22199937668d0ca25f8406cdb144f60a95dc722b8642d1

Manifest digest:

sha256:ff86a754d637f780cc2091844692c7e38c0c03112aa7cf976f3b8d3cb80857dd

Size

1.08 GB

Last pushed

15 hours ago

Vulnerabilities

5
36
45
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:7f7c2b18e26b986e863febb5c521076075c0418ec29730a4b9c48d2113a34650
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:b2b1f9fe10c50987688b7adb426a6a1a8f5d17f0942ad0ffe41113febc44b1fe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:275657a1cb61d739c24e0f421cdf488efa1f8b6021e0239ec3483e1e9bc086b8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:cd0b2236bebdec8d8f9eb5a3237e50e90a21060cc210ec4fe6406a717ec12bbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:7471df2114b3097a638c855355f95d829e56ac781d95c4af47e68df69006ad1c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:6ce91f356682534f9ee85a01fbf8887f605125b1d8053344bea17e600f925c08
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:c30cd9758823bde1e16e05bb4e7a0a72d66fa086079d5b08545c209365cfdc66
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:79f0518a7e0d1e4e28268f99b16799e5458c91368d8f2c1ecd3d25e8dd857665
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:046bfe07e543328bfd05524a11c57f7a75b37d366d198bebf5d8e448bb972a8b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:6247d91279c4c09980c7074322f102b40568f5aa747a2989da3590973e85a3c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:66244c97bb8ed3ee449824d89205a8d8537e3f2aab864069e926bfb72285b227
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:7e21caa5d0600d026ca9ffe6f6e2fcc28d72abdfc6223b284f90d81f1bdd2ab6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:f5887440b5e68583c47c8575bee0b0473452666921df801440ecad5c84695b6b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:dbeec925603ca15b5013f3ad474956185cde8caaf0d5f3d7392484a6aa5d5152
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:f01f14980b1f402d745fdc5f3e7b6c8e0d29c0a56e3a43e1f0998a349442a77b