Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

36-debian-fips-dev, 36-debian13-fips-dev, 36-fips-dev, 36.0-debian-fips-dev, 36.0-debian13-fips-dev, 36.0-fips-dev, 36.0.0-debian-fips-dev, 36.0.0-debian13-fips-dev, 36.0.0-fips-dev

Index digest:

sha256:d7610d299bc95731395be63e7829ac6524a691baaa982a3047d98ee74e7a9c2e

Manifest digest:

sha256:f93c9758a62cd7f31c0bf58f6ad5eefea992130c270b2a6c271893ee62f73642

Size

1.09 GB

Last pushed

11 hours ago

Vulnerabilities

5
29
32
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:4dfd0e7ffd812715659f7bb0e3cc893b230fb5bca8c9d7b3da4a7b5befbad4ae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:85b0e24feef5b389f0cbc20792e1c9dfb43d2f24f573ddd005ea25d3769d7a0e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:9eb367ed15dbee3265bd9810200bdccf0e9ae1ebf62570aef9d7abd544c7bab9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:3027a516e53666dde589c125d3663eeda652c646ddf9d65b66d8b41e2179a02f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:fe048350690ed6512e8380cb7b785d03651ed9846e6fc5a46b685ab8a702f34c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:65ee001b2df1cc60d9f99b255361ca29caf0a8cb73aed0e06433d460abb24c37
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:5d2a5132ce8138c4e97e25a0e88d0280eac51b1baa0a3fae28080de7ade61480
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:278b23d97b4d9d409a66ad797cafc6c3b059ed3b5c906184990815baa341fb76
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:e2abbf49a861ba507790809acebd9578c31a54dd5b2564973e75e2485266415d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:7545b113e59f56b8e74149f959bbd28d00dc3f52622764a975fb34f8836f56c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:2f47e232e9cf89836be1aa4c99849e3dde2814b638285120d2ae10696baa634a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:4e850c53dffa42310ddccffe5cb5ee99020aff51f72778c2ab7556822622e84a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:b6ef0ed6db8d0bf192efc110959bc254bddc6f3833a5f925674ee2b135dd7ca8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:4feb781cbedbc3fab4f188f8908adf1477d77666428f073b59a8c82d738a5aa6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:352396f7ffee357dee44f77cf54f1cf025cf761abb20385d1ab4db2c48c38721
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:e140dfc1c72ea21822947b7c8bbbcd38a67fb66d0ffba71dd56b7695be7dfe30
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:61bf607745edbe3941a8eba1764e998b915e59657c93b1f9150c03bb6a189547