dhi.io/solr
9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.10-debian-fips-dev, 9.10-debian13-fips-dev, 9.10-fips-dev, 9.10.1-debian-fips-dev, 9.10.1-debian13-fips-dev, 9.10.1-fips-dev
sha256:273336e09ea6ace8ded96c32bf628312e1a1001ff81e4be710322eeb8e44abfe
Manifest digest:sha256:f53f2a959948da77ed00f652dd69a40e2deb315d45483f5bd3e0c74ba1f27d81
Size
134.61 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/solr:9-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/solr:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/solr@sha256:255d3876e5be4bb9c98b47cd1a40d16fab73620775b831b75f41b0e51da9419e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/solr@sha256:d4acbf9b0b4f258dff8e69298f6256caeb43d783b4060d4a7b0968c762891c1e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/solr@sha256:df755d6edccfec4d5790c7977b0ea12f91495330be6d269d9bcad2329b1dfa0b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/solr@sha256:0f11326e36f086b31af3d47b541a48dd001634bbb6e8667a92e96d3fe73138f2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/solr@sha256:f1ed201b601297c146e82c338fd56946d8342801e7356210b471ae421f45b767 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/solr@sha256:055d0c94a6926de12fb948b2e62f0634747c784ba04658baa78be174bcf42bbc |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/solr@sha256:a26922997887d6a28055dd4508effe830216b5b989f2aa0a6204a1d6a1ffc803 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/solr@sha256:6adf2e9bd03877a18778c2a2b54844d4ca4d5ce22a89830173acae38c8d317b4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/solr@sha256:1d731723433764ce73a390ffde12ab92ea7e292789493ce5e36bc42fb953f37f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/solr@sha256:bf237894adf42645451464c4575979c0ff6f537709d1fd20d5927d6b192ad9a6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/solr@sha256:1080f8983b811916cfed06c65abc2ed6a30bc70b8c52c86690f8f9b1085d1ee5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/solr@sha256:c945176f8dd8798314d47f9e52d8c576faa95828d6d93c26abb63cda349b0189 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/solr@sha256:ab91aeef677b948702af991a4940ae0bf9d5a9802e9fd8662ad03323b349cb56 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/solr@sha256:e532ea09779b57a6b637c5e4307d11f2a9fe29c7836d1d361c59a029afa599ac |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/solr@sha256:62fd6538e32b76ecc9ba9e49ad97c0196a4b2c5148d5e777847b50c472109547 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/solr@sha256:bca560e48524176fe6560b71bf1fdbfd2e07e359829122bec840ff13fc510bdf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/solr@sha256:43ec4f3cf53c25cd57c6b3df75cfe120e4530086766589697b24659b906bdcec |