dhi.io/druid
37.0-debian-fips-dev, 37.0-debian13-fips-dev, 37.0-fips-dev, 37.0.0-debian-fips-dev, 37.0.0-debian13-fips-dev, 37.0.0-fips-dev
sha256:00b779a5752eba20a2058a0e9df7143a54c489ad0f3c8028f168582d4a4d69b2
Manifest digest:sha256:0c4bc3f0cc3eef28f4cf35f717abca9b18c4777696ed3976fd67c4c44d1040e7
Size
1.10 GB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/druid:37.0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/druid:37.0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/druid@sha256:182271ff7909a9ff7173bc1a8849d4bba1a763bd632e07b50371d2eee7ad06ae |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/druid@sha256:825cd182203558c5141c2a5e6b641d6b9f71f0a2818a335e59d41ccab55a68c6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/druid@sha256:97ab5c4fc85db1941e9c122ae1011846762627c6ad7c9d11fbaab611c8aa1399 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/druid@sha256:1a60e2c2793cc006d29b1a167edc4ab4174dbe5f17a45861a6a9c5c61215007d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/druid@sha256:5a8315454d489ebee58b90c82943a04b747cc7f58926ef8f3291f9b37a5a0fa3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/druid@sha256:565cbe1616eaeda6e951ed7f200e679899ef48923cc12c0f4448628075f2b124 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/druid@sha256:32703392965000dcb6c10efc0444c54e2203f31a8e4bcd1102377d7628a01651 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/druid@sha256:62fcaa472b7df8e32b47d77f4109cf9c5908ccde94a9c2c1d7f66e54d823f506 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/druid@sha256:c60a4c5f280c964cf8f9d8844d8f1f692bb7a1734f77b73747adc6ea6843fc8d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/druid@sha256:49d5da1fd4fa4cfcd1857a71316f4e21a61fd578aa23cf4ebfe6506550817c84 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/druid@sha256:e170571173e1038cbf43e586c8eb3b6a5fbe9c12ef61e74b473f55201cd42f37 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/druid@sha256:ccc8cfc7ab37094f1e14e4a744f84350c24c1c53927facf625c4be95195fc47c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/druid@sha256:b073d51929ef8347a3759dd8a14f85a4768fa59ffc6aaf2eeb22cff3d1139735 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/druid@sha256:6cc2492f4f1bf35e0a4bdee7ac906f2a3446776d5401cda26a8e90bfc690673a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/druid@sha256:c5ed842c8c3dfe06167b4090bcb9063c5f472fd8cac7b53de80250ef68de7bae |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/druid@sha256:49c4aa4744063cad47a0a27afeddb5abf94aa77121f36c42dd0d76a2af99db85 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/druid@sha256:2be06c303fd78d7f4316c064f050a0e736bdb31d6aa501cd04e62f20aff0b02e |