Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

36-debian-fips, 36-debian13-fips, 36-fips, 36.0-debian-fips, 36.0-debian13-fips, 36.0-fips, 36.0.0-debian-fips, 36.0.0-debian13-fips, 36.0.0-fips

Index digest:

sha256:76381787746d614973f3c3b8ef3aaa67c0460dc7318894947624497d32f939d4

Manifest digest:

sha256:435bea62469bb83f9c216a69632e687eaa13e6f84e05e1d75c4fcc751faeb990

Size

1014.14 MB

Last pushed

7 hours ago

Vulnerabilities

4
26
31
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:851b450a8843f4652e307eaa80b0be500b69cd0b45a8755a259334305388a258
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:bdf88563b2d80d357e1f5455de242fd8294166bb245b6dda8875d19f2c82688b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:24113e17ac69a5d76b8de353cdeb5724e74bea0e570b0342b1021b6f335f14c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:ac6c98f71cc0276105d5bd7515a2eb7ded722a0c8921e5fdbf299d341b6cf660
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:969a1f0625b1fd9c7a52543fda398cc3359c4b8e9a2ab0dfe425a6e8823111e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:c4210d701cb851c102da35db057cbe128b727ca9d9529dc55f13a4954ccc26fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:e5a07d2a3875ed85ede418a1150dbd5ea1328f832a62fb7273722db5106cb94f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:ba7e1cda01a687ce5c11ab326508f1bfd149801a5fb3e55056ee5e2cc433950c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:6c57ce00c864b5d8bab07716c12ed83e97046d97ab48fa51a12005fd4bcbfd03
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:3fbff619ef27c78eb75a4b82b745b96116ce7b250a030d43b6a54666631c8a74
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:11d5db083eeeaf918377baaf70977da4c611e7af2510a96d1ee21b32277a9e7b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:a8d11320fe574e68e753fcd1df76f14d806b651c9c84239536397fd013602f75
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:9987ba3d7896471468093f72402c7c317ca37166c076fb6bae2630dee6d22199
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:b2e50c98cdf5d31ecbd472429bd701bbac503d0939f9ca4b0fdf008f96a3834a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:d3259ce96bb07327eb6626b386e22a65b88cf09604c65dab88d1b0ee4070652b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:6a3ef312891069d9b1cc60d024f58adede327735c9fa38e1b28fc4f486cec711
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:3fbced92eccc88969d7fc78cad60a10566399dc42cdf8766c2d9ae133142611e