dhi.io/druid
36-debian-fips, 36-debian13-fips, 36-fips, 36.0-debian-fips, 36.0-debian13-fips, 36.0-fips, 36.0.0-debian-fips, 36.0.0-debian13-fips, 36.0.0-fips
sha256:93dab2b68e3347cc57290890974e01d604ca5e396dc7de48d3e3c738366ce211
Manifest digest:sha256:05a0b58e4a553b5d37602acfe56dfab0fe856e7daf9e13e76858145c0f88bf6f
Size
1014.76 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/druid:36-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/druid:36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/druid@sha256:99491bb1fc2a880704a68a387f3beb4f6adf8a28270081b9aec0cd1eb8bf7cca |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/druid@sha256:2102426f1ba79a6516c3c98f7e0ac3dd3384e312fccb10ed5a598fe4739e09bb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/druid@sha256:0c59cab0dcc9eaa0220737bd017cb8bb4ea0ba8d2a5c505c90639134eba114d1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/druid@sha256:0f17f6b458b8b92d01d95bee208f442c85f657579d4029ee41d1f82daece8586 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/druid@sha256:69be40c96aa02092da0e1da1eceb755131280e278d19707defb448544b3317aa |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/druid@sha256:07123fb61d4b8775f8ce086ffa0e1e0ba2edd59726a30ce29364cb7e70fb7171 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/druid@sha256:b9704f94870bb0817910e3e8555e69de8e2b855bf984c3d5cc2c9c4dd1614a33 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/druid@sha256:144cce988993f158c58582e9c3b687ad0acbc520733ce4980250d05cee2d47ed |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/druid@sha256:a506978fa2aa1010c2e2dae15ed9a9839b2cb6f443e64922b42d851a2337d1ee |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/druid@sha256:beaa417460d65e335828b5cecdf54dc0394edb1faf037aba7d2b7991dbf5029a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/druid@sha256:e1e3159a5143a2606d4802634c4f24832a6b615101b996f8e1bf83369374d7a7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/druid@sha256:9f073871fba8c649c1e0cbb50448910bcd601bc8c0e4d5d8164adbd2cf7cc8e4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/druid@sha256:300beb006029b59f88e3ca7798e2739b38b18ab85efd4f4d21602990488c6383 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/druid@sha256:4779611523396e2ad52270230f4548be2fbd0f29ab01ce425807523307e40302 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/druid@sha256:4b7e56dad82c1e133f91a628209f57068d01ff8c78ccd75fe9c0684a4ce5f785 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/druid@sha256:4d883534048ddb3a0e4aa79e518a99b7aac35ad9a64809bcd43f1c42304034c1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/druid@sha256:812a2dfbd9c1046ddf706565226035cdc2434bdbd0229e2c9122010e6615c0d2 |