Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

36-debian-fips-dev, 36-debian13-fips-dev, 36-fips-dev, 36.0-debian-fips-dev, 36.0-debian13-fips-dev, 36.0-fips-dev, 36.0.0-debian-fips-dev, 36.0.0-debian13-fips-dev, 36.0.0-fips-dev

Index digest:

sha256:7cc148aa3db663b6144ff9b573cc312103ffe82ba843f48488d145ddc1b8bc7d

Manifest digest:

sha256:0f2539a344d4005612474931529e5da50231a582f9b90a91d904ef9a07aa1db7

Size

1.09 GB

Last pushed

21 hours ago

Vulnerabilities

4
26
31
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:86343badfb78f38ddc6fbd1752894e992c4c8e1afe8fec9b659b9049fccb4978
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:cc32ec652a55b594b6783938973e047d83dd0929e1c021b768a028447e56d496
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:cc0de669259171ac66bac422e3e602f6d5e4a5c4e363e24c04a9de192baf797a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:ca309cc494e8ef0589b644483d9931c2d80b7ffd47478f7ac8e36b1ef61a88b5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:ba5fc97e54ab1573ed5f1f185da39182aa7d6042712dba1d2b4feadc3ca4d135
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:4691181d2df8363ab35230564d03fb9075725badaa0c266a6d7cda01bc5ddc71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:77dc8654362dc7f137d398bfd173821837d23ffaa5caa54e9e373db409207ef9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:7283cd41e3e047324cccc24e81cf9b594d967488de8fc9f60c632f5cac26485b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:d9d3e538e9ff73eec89444d0c1fb67307325a32f26e6f877f6a8a24ec544c1b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:03909f713a3a7705f1224d79a7f9ccd214522c9244323f10681eb9e4f221cd71
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:8f89435ded6feb3b8db04fa59d900b320b1364c22970e0037d7a825fec93b4ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:90098d54f3710c2c71afc1cb904c91821960a2b5246afe0b35d1f9025f6f1900
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:11a3a5d4b26abf428e49bd403c239ed5d19158af64328466db5a4d447996cf43
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:5f527e25a292cda814c2770cc5f0920a69d1a16a46ce60eabb52746ea12b99e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:12622a9f424bb8ac2cb3de402b7bd9fe8b5468a3f3d89b663c39ab34ff041ccc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:b0bdbf14f60aac88930c012a3afe953c25a68e10acc3ccf87b7474a31bc0dfa4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:42b91e5ef20cdbff0a1add91b2ede802cff597f48062949a1c6762d8c08d9f58