Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (dev)

CIS
linux/amd64
debian 13
Tags:

37.0-debian-dev, 37.0-debian13-dev, 37.0-dev, 37.0.0-debian-dev, 37.0.0-debian13-dev, 37.0.0-dev

Index digest:

sha256:9c05e48e5bf0810da718eafc062b19c1b539dd9317fbb1b3f14f161a4ad46dac

Manifest digest:

sha256:585180ec7a55893f6620092816c9c21f8df5773884a04fe261dd3b3c017e661e

Size

1.09 GB

Last pushed

5 hours ago

Vulnerabilities

4
31
41
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:d0992a5c07cc857ed5a53113d2d0aa87114fba72b6ac3f40a03112f2eee27e00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:9738305f83012b17e526413531370d72bc5ba57dfb366b040277ce3bdbaaf24e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:219bd5f9ac00223e602a976307606f8f08bd165ded4cc8b2587938aa9c4b864d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:f05bfd142df0b0a5f7a7035c26de3a14189920b30a78277c50b0ac3728153198
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:db8c9ad632f98c71c3fa620c8cd23336934aac67f094d52a1dbe9cd9fc299e26
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:b8738210d14991cfbe71bc3b712eaa8ac75820429c2666da7ac91de954584ca2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:9719d8375e20c60d855ae5af2f8126b594eea213e180db6cce4874ddeab71584
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:fd001f43317193ca5fc3c5a27b5d14ce9c301a356fef2baa5174d62620930380
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:3239f6dd70c4ecfe3143ea527561159809fcc902043dba899236ed033234db65
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:92a03b3d61c85ed66c47ee4f0772ad6058f1b9e6ff17d0f516d046ec862d2054
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:61c931c465ef67aca7bce5d107f46777e9a7c4e38610f093967fefe43b8c3209
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:023de12396a34599cf902f716a2188f09208984a077501e64721648415efa4e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:dedea7675823fa5b4446c8f7afa886d4eabc07383442d3ccf7466426ba4c67ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:e28cd7a377fc795d0948b92e95c9bfbee478a9141e0a20df550aef6f973873ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:59463a362b1ccad038302773b76baa38bee637cd225686a50a1b178af2eac500