Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 10.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-debian-dev, 10-debian13-dev, 10-dev, 10.0-debian-dev, 10.0-debian13-dev, 10.0-dev, 10.0.0-debian-dev, 10.0.0-debian13-dev, 10.0.0-dev

Index digest:

sha256:cb2da79791c746e45b987d87bf12efc38da0fb5183625f199c5ae6c3d8d854a6

Manifest digest:

sha256:e0024ffa40020a5a9b01f9293f9d7c027eded589d6ba4ff400d35a2119c3bde0

Size

135.21 MB

Last pushed

3 hours ago

Vulnerabilities

0
6
0
15
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:10-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:95a90afaddd8f6be4cf4a58887777afac2e27a08600eb13f714a1d55eb8f7bde
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:9f4a6256889c02e030cc18e7ca7629043d18b4613f6a8de219b4c8afec8b99d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:c654ae5976c17d03b6471c86682ec54defb56510c023702c3c84e28d616413a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:099e0e547799d7c962eaad7cacdedec109c0e67570f4d27cb1835fab433e1f42
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:5a47792f868d065bc7689ec7a89a89fc3162dbb8bb91827fcea930afca085acc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:67f98e9652449c62814797016c88905c22a32770c2443d0aca7ceba79b8cea39
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:7536c295ccd57745543ebe4bd6227fdf6fa52215d980c2f19c2252df17367a71
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:c3b6fc9be672d601d6096c19689dd2761f408c0acf1604e48d2aed4b58313459
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:fcee592e152ea2c9a4666217db0362373b12692c01ffeed3e8ac53e4662761a0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:6efba05d842ff027c68af4fd31dc6d8b4b2b913951ad0a1307eabd3e92e12eae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:d08e4502da3686dd58a0238112883bb1a52b7574f857a1b173faf0b82a21326e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:35d718066ec2ae2b8185affe26ca70b46b94df6396588ab35f0b2a6011ca8513
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:73721d512f51583d89b3af861188c11f1243a68ab4044769be9dc4b81649e1c3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:bb5bb894efe69a5208a188c2d257bff55d54691a23cb9bf363fcb9a6f89a28fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:95afa7c850b74259338ea846b3936d32a7d1b37c8c5ac8f2cc172efa62a6b5db