Sign inSign up
SonarQube

dhi.io/sonarqube

SonarQube 26.x

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.9, 26.9-debian, 26.9-debian13, 26.9.0, 26.9.0-debian, 26.9.0-debian13

Index digest:

sha256:8f581dbe440240b7a6c5d3aaac7513185c606be385e4b4ae7a864ef6cc71dfa1

Manifest digest:

sha256:c9fced9fc775e31fa5ffed3652d60f82dfe0a4065f5421c0f4cc4aeb7c195f74

Size

1.00 GB

Last pushed

21 hours ago

Vulnerabilities

0
5
6
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sonarqube:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sonarqube:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sonarqube@sha256:9ac1126a67fdb7b681eae67f7e07dbc6b1667be6b8329fd5b78db75c8e68a5ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sonarqube@sha256:453b6c742cce31fe38b990c773a30b481438e8eb6cd7cbfb0d810252a9162539
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sonarqube@sha256:acdcdee0071f3ed0a67105d097d94f43349d9f1ac8e30183eee3244835d83830
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sonarqube@sha256:7e70197a3f676f70b9991022acc68c7ad49637fd58af58469aa1f7b22dc9134e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sonarqube@sha256:70aec96ee137e3c1b5d610d35a099070cc12d1a4544fdb0200200355b4314bef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sonarqube@sha256:114e37f8c47a84037073ed883b3dd03af19797f0259bf7e2d8841eeac57a9fd0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sonarqube@sha256:e27428e90e7309b944c7a8ec59a080f786d382b45e2f049be167bcf4df1b4b04
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sonarqube@sha256:a1c2e0549b7c2753180e2bd54c599a29080d677c1e1384db8f5a8b589ef54045
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sonarqube@sha256:befec7a9957a2e9791e8475b2e43fa6ed23d3d1603c1bc41a014a7467b721919
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sonarqube@sha256:aede168bbc07d4546abc7dae106d169380a2eefdfe1890c32598f3f920b0748d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sonarqube@sha256:d5f20c2fa9bff9d3005bdbe4a015ca6bf46f65ce84b07ca7b4fe49153b574b0f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sonarqube@sha256:87d621f61cf35b279282164c6d0283da736693a424753f502a052b1d2b18c882
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sonarqube@sha256:ada7d78ff93881a3e830788be32ab4d5301a730bed1fcaaf049f31acd04b7de1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sonarqube@sha256:b0465abaf44c7b0f81e351e51c58962193a3b9a5c21a2b51273cf7881cf355af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sonarqube@sha256:9cea5f047444a5149a4ad841c410c3f8c7f518a633f6e0f610bd9020831dd125