Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

37.0-debian-fips, 37.0-debian13-fips, 37.0-fips, 37.0.0-debian-fips, 37.0.0-debian13-fips, 37.0.0-fips

Index digest:

sha256:9b74a0b3308683cf728488bad54e305c805019b61aa97585be7d57265decacb0

Manifest digest:

sha256:504100b306ab33cb86b80cf1ef9e2ebb81e8e4a32143c1944ce3a474142bd85e

Size

1.00 GB

Last pushed

15 hours ago

Vulnerabilities

4
31
41
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:22d6d9d00a7a03e31ae4f3c7b74b623066a06725d956a7ae840c579da32d872e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:b96c1bbc7afe03c275da7854d3d8013bf36b058da057eb7ba2f5225aaa2b9ff6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:9f96712fd809a0d865340eb6ceb0e4368d03a4389dc38b7ec31bdd8fb944a0c7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:d860605a9d1074a1adb8bd62face5090ea6a29972e1cd6b0495eeb63347a2408
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:6a2e26c78d6dd9feb243480e6942328cc88ccddf8dfe6039f95496fa65496ad2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:55a78af08f9f07e3da6613aa5bbdf56837fcd59b08e566e16c42538fa0c9fe1a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:650da63a701164f6db8f2c95eb31f780d6a49e528bbfcbd6d02a8e9e83f125a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:c7d488862f09555b27489ae2b8ccc27fb2efd08fc2a9684eda148aa1d1c718fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:d2cff06ea77d8b6495e90cbc4263731bcb097ff41dc0b3ddb96c16894279a1e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:aedbc7ad6c6c5d13cf4677fac68417bcdacf91724f80887b35667764469aea16
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:65bfa41846df3a4b9dafd21b8f93ab700a1d8d69c7d8b79f10b5d02ad48d5bda
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:adb89831359fe3c672cdd4214a6217d64f28eb2cdd3be237533c376cfe6399a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:a2dcc3278d111a6d138f0aa4de82128b6316f6fa007b599e70448f112395e1d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:f292015f72cc8b1c6d2e417dc354fb9ea1548a0ebabb5b14e5229808bc7744bb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:1ca81454177ea21a35f331a8332b0d12400bfaca8d336efc45007535f8becbd3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:7f897d582866040207bb4d8802a3462d47608bf1e218619a959c8e6c491b5560
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:2658ce28ab06b34c104dddc4d5b00d22c72e942c9c85ab177d6724597b064a85