Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (dev)

CIS
linux/amd64
debian 13
Tags:

36-debian-dev, 36-debian13-dev, 36-dev, 36.0-debian-dev, 36.0-debian13-dev, 36.0-dev, 36.0.0-debian-dev, 36.0.0-debian13-dev, 36.0.0-dev

Index digest:

sha256:217e58b3f97ef0ba8d60359b578df768a006cef83e12752ed434d00726f81817

Manifest digest:

sha256:09c16ce290278e21c99d7df8b1fc5f7e28a4c18bddcb40685588ae59efa03104

Size

1.08 GB

Last pushed

18 hours ago

Vulnerabilities

5
28
34
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:0c6b1f83c88a17ba922d4a79d0c526e3150fb824e4d017616dea00e9eec543ad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:68d07c28dc2e0ba1db93e756e5ca7e462eccb3ba3333e108a87da1e8aae7e75b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:ed3c46d5bc02d5d01ff83cb940ec87076d40adcd0cf46611bc445445d6605314
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:f97801f51ce51191d0855c3f953bd44394f49e22828d602112e49be875ce2ba4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:74aa1d808db7a1305292630d2bb4088651890a96c7358d3257b5d42a50afe82c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:7ef14856185983532f30c784b10846dbec14936f5338eef52cb07dfdb77e0aab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:3e5ec43e227ebaa902082638a9050a5197d873b1002933a31749bed45fe65e5f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:f5ab51b90936f05f98d8377f1e4b845c48a8174b6eb8b53572170047fe73178e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:b7c3b41108291ac3cd5406272d0040e97d556b8a83608dd7575a9404fa77c9bb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:0b7aa11c905724a51836949dfe7a0d6d0b72966cc5d2011c19e086f72a2f4773
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:aa2be907215f0f858d39922d99aee776c4e27b8d4a6c13509e0d5e8d681f2c3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:6f22fdca1dbe565d19ac6f3faf310211d75a21d61594115bedec66431fa63d50
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:9074e206424c74f2e4235c209b72d2ed23fa5171cc260fff496d1767ee186d85
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:4682f50bd333cc57125dc6dac00ed0d357ba40b5fcc9408289283a50221262d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:911692dc4465328773e80998c24d30efd19c4b93f21de232afdba34ef4bfcc76