Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x (dev)

CIS
linux/amd64
debian 13
Tags:

9-debian-dev, 9-debian13-dev, 9-dev, 9.10-debian-dev, 9.10-debian13-dev, 9.10-dev, 9.10.1-debian-dev, 9.10.1-debian13-dev, 9.10.1-dev

Index digest:

sha256:b245b0b0b7d31522b427e75a5e1fc2d0217b69fd87a9b254c735d65aa6afbf8a

Manifest digest:

sha256:8c14bd2e7af33b9b224b3fb8eacd14bbc8e933815fd03405854a7c3d695ce15b

Size

124.14 MB

Last pushed

9 hours ago

Vulnerabilities

0
5
2
15
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:cce561807d9f2783d22947b3bb38d50c50ec3d6f3e0dfb309ecb370372e930e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:2f594babd3bdd5e54c9cdfd8f3aecbb27d2495752c9c6357d48d577fce988a3e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:be126f5179b5b473708cc38581ff6795d2482b6bdc4ed5830975489b0c4644e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:b81a9d24e7f29f0b0396fa53b1da5dc10767799a7267f1a813122c136335c344
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:155cfa1651d77ca6662b46790ed16e69465ea0c518da37654514d19a44169a01
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:9427f61661f9017bcd1daa3220f26bfcb4589622294aaa3b9f8acc66c4e3d9a3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:17653652598fbacf1f8a169c6489b090a4d66a86109b0bb6350eabbe0328fd9c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:9cdf566549dcc229cd91ed5515907c702461adce1b62fffb0dc466f379573646
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:93e18b2a0ed232595fd4c5f862f07add3f3d0a44ef32789eecc520057534035f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:d0f62966de10250e785d59f7e478bfc2bb790e9914931ccbfbac9e809da4148c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:467f6c9317b328d0ca46baf609596c4b10364f1041209f198d4caf437b34a100
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:71425c4961b3592cc8f3857a54ccc073ee5b605ee27a91d6cb2052208bf4806d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:84e592208ffb53ca2fbd8746a9a3d0c1be7ab8c00e080304649559598b2534e4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:95f7122f6d5add4646f6a4d94af76a684bce29652240ddc7a465764ec5b5d23f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:4cdae6c8bcd18902ca33d72b7d0e6621c837061ec48975a2d03f7c7ae72ea316