Sign inSign up
ClickHouse

dhi.io/clickhouse-server

ClickHouse Server 26.7.x-stable (dev)

CIS
linux/amd64
debian 13
Tags:

26.7-debian-dev, 26.7-debian13-dev, 26.7-dev, 26.7.12-debian-dev, 26.7.12-debian13-dev, 26.7.12-dev

Index digest:

sha256:8e569a91b119b0184404b027cb2359d771976572ee0baa37aab9c887d920e8ad

Manifest digest:

sha256:18cdc0efcfbbed0eae2bf1d9a3c4afc16abb4e25f926afa837e92d87153b6992

Size

191.96 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clickhouse-server:26.7-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clickhouse-server:26.7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clickhouse-server@sha256:bd70924e9e2b855ba9d54dd8747511df643c98f7cc40a23630cd8dc81c66e748
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clickhouse-server@sha256:5fdc44ae6d8e17f6fc9c052cce77fd4667d846f81721057ece88ca44e5c8c233
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clickhouse-server@sha256:75d460b1cb4a20a6f6666f5621603ddcdbb5adca857d66bf1b99608aa3c083dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clickhouse-server@sha256:d2774cf007d02157e20dd52ca8d85d57d6d037f6b27edd45c4a66128e2887d78
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clickhouse-server@sha256:8afbf4be4d0090d9878b509f8abb0c6e54192af1e76795a463ed22568ef09aa1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clickhouse-server@sha256:b67abab31d8b5dd91165fda57bb70343f088a3ca9bb2f91e29bbcdd9383d379d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clickhouse-server@sha256:cbbddefc743ca515c240f0957a0ffcbca531e13bda9770275c93925030c175da
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clickhouse-server@sha256:e52dea3d41cc6d46da589dae9d776b50fbc5f1a0be77743af938f428163ee286
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clickhouse-server@sha256:669a92f6c3c6baa6cb07ac7590bc47ffeb806d08862d66b8e9b1d357294a901e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clickhouse-server@sha256:6ac14678f77a4ae0dde2de4faabe5b462bdf4c75013df7c76d7ca04a6cc1a12f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clickhouse-server@sha256:e807ac1ad2ebc4064692b2cde15e08dd808fe62a2ae49d9db4ffe5e4c1485417
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clickhouse-server@sha256:f7d643d766d6e2c7d3fe8a5be81ca2da27a86f96a257743884acc1a86758e02d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clickhouse-server@sha256:0121d603088a2d0526bec7e3b6da623d79ebbf166a2dd6904cf80cb2ad2e73b7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clickhouse-server@sha256:624924108c15f5377d092c4502c52c438b51d78e0dd1e59937cc960b54f71300
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clickhouse-server@sha256:7f000574314a9f951cb493bc10c63d37f0eb26398c82460270c65abf759071f6