Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x

CIS
linux/amd64
debian 13
Tags:

36, 36-debian, 36-debian13, 36.0, 36.0-debian, 36.0-debian13, 36.0.0, 36.0.0-debian, 36.0.0-debian13

Index digest:

sha256:ee6729bcc4dd436d5f03eaf16536049c857b63d2616f843c813a3310ac21836b

Manifest digest:

sha256:661aa8b7bb2d97924a8779d2c4505a57dac4b8783a8fb2e0b2f6900c0f208ba5

Size

1005.05 MB

Last pushed

13 hours ago

Vulnerabilities

4
32
36
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:3384dedcf3d633a88f6849958d4d76cac1d0cf28c16e5dbf3da24e05ffc76300
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:a568646ab9735f8cde301d4a61616dc03081f94c859f221a8ff11283ea137a40
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:47c2e6c8aab009ee5036035929f848a7ab7003c88fc9789f003e1cbcaa19787b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:5fc7f9e517158108a0e2ca3b2c219137fccd4548d743fdce250cf3a80ec3a328
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:17042162a35c979b0c4830ff05534b6637c7319152f2f8b24d8f1bc72a8e03c5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:a6f6672a75390682c10f0d92aa10de2d33bee8d56881445225c2d8d7e9d9ca47
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:bf66360cfec6a4b875a927f971432c2ab386fa72ded4cff5dd86bb425a9315fe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:146e859851b9c410cf7d4c0a11a47c1919beef9b67721002c7a0b3d620390273
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:4be5377720dcdad3e7c31269924f5052db36c7570a1d1bb4d7c820212655c112
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:6e0a324af3696be95955d477495e35c1788327a3da10244674f849da86533393
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:fa573d80bcb117fe310671d86ee1c6e34d968646775468056bf681604cf748fc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:da1bdf98adcc3d444d3c199c5a2bbd5b914c83d2d5cd17ddc9439eb2bb952282
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:134724b9bd8c19e102b85f7fd97db8f8a213eee903f62fe50ebb05980c36d9f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:e54b86465cdb06d028b840e3c212dd8b70b1f1e5204789dbe6cebb2ab1759d55
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:627ae2824bd8305dd58f083f2bc03cdbc248894c3144b57abd430e10b32b0728