Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

36-debian-fips, 36-debian13-fips, 36-fips, 36.0-debian-fips, 36.0-debian13-fips, 36.0-fips, 36.0.0-debian-fips, 36.0.0-debian13-fips, 36.0.0-fips

Index digest:

sha256:93dab2b68e3347cc57290890974e01d604ca5e396dc7de48d3e3c738366ce211

Manifest digest:

sha256:05a0b58e4a553b5d37602acfe56dfab0fe856e7daf9e13e76858145c0f88bf6f

Size

1014.76 MB

Last pushed

2 days ago

Vulnerabilities

5
37
46
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:99491bb1fc2a880704a68a387f3beb4f6adf8a28270081b9aec0cd1eb8bf7cca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:2102426f1ba79a6516c3c98f7e0ac3dd3384e312fccb10ed5a598fe4739e09bb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:0c59cab0dcc9eaa0220737bd017cb8bb4ea0ba8d2a5c505c90639134eba114d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:0f17f6b458b8b92d01d95bee208f442c85f657579d4029ee41d1f82daece8586
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:69be40c96aa02092da0e1da1eceb755131280e278d19707defb448544b3317aa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:07123fb61d4b8775f8ce086ffa0e1e0ba2edd59726a30ce29364cb7e70fb7171
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:b9704f94870bb0817910e3e8555e69de8e2b855bf984c3d5cc2c9c4dd1614a33
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:144cce988993f158c58582e9c3b687ad0acbc520733ce4980250d05cee2d47ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:a506978fa2aa1010c2e2dae15ed9a9839b2cb6f443e64922b42d851a2337d1ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:beaa417460d65e335828b5cecdf54dc0394edb1faf037aba7d2b7991dbf5029a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:e1e3159a5143a2606d4802634c4f24832a6b615101b996f8e1bf83369374d7a7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:9f073871fba8c649c1e0cbb50448910bcd601bc8c0e4d5d8164adbd2cf7cc8e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:300beb006029b59f88e3ca7798e2739b38b18ab85efd4f4d21602990488c6383
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:4779611523396e2ad52270230f4548be2fbd0f29ab01ce425807523307e40302
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:4b7e56dad82c1e133f91a628209f57068d01ff8c78ccd75fe9c0684a4ce5f785
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:4d883534048ddb3a0e4aa79e518a99b7aac35ad9a64809bcd43f1c42304034c1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:812a2dfbd9c1046ddf706565226035cdc2434bdbd0229e2c9122010e6615c0d2