Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (dev)

CIS
linux/amd64
debian 13
Tags:

37.0-debian-dev, 37.0-debian13-dev, 37.0-dev, 37.0.0-debian-dev, 37.0.0-debian13-dev, 37.0.0-dev

Index digest:

sha256:c4050d8d8f7ad2d9b50e2d2cf67a0af19a0cdae4708312f252b99fb72a0bdf71

Manifest digest:

sha256:cba6532c4f21a77c62c2c371ecf7924fb9a327002c17e410654a86834cf6ebe7

Size

1.09 GB

Last pushed

1 day ago

Vulnerabilities

3
21
27
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:55a963da69ffb979fe6ab98eabb30a29b0ebdc96f2c3d7a5a4e9bb0310eecdad
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:d9f7960575f9b301411facd6cf6d404a49515c131f81d6b8be52e3d427186f76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:e64e32b9cdde547293639b20f3a339e1344ca8b73a0cce82aa22a438dddc889a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:2ac72894155b5c38468a57934082ce9c074f5d9d3d1e6d2ec5fcddbc5e09d77d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:5b486553bba0362a4123098e847496cdd2432ee77febf8045c79c61aa84d8322
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:e255da9be12545ff35489add4bd68972c99fce98a6b904c703adfef066e2658f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:644e89548cd286f268d7e41be78d40bf691a9ef15a74cba324ca6c21899f59bc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:0e2acd18925cd8be219cdd8e7dca968d02d7f0705af37d92cf930d281c493504
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:2995795abc477facf74261ae89ca75ee05ff78bc95f429d693fcd4905bfb22c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:a12d4ff1caa2426aa42b75511652c5b932e12afb72e4a5d71ccb974f1609a207
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:77bda79f8303e4a4e2f74a557b9d792be587f8ed50029cf07ff63e4600d45582
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:c6315cfdcb3ebec83a9eed4eba242de6fab2050639fd3235cd690753bbffa279
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:3210887826c70ec369631cc8dd5fb21c706bf3a84ecee13cab49c15afe41ead3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:104a35328b21e1312fd138c29de4372cceb578f7cfcf67743f2e52500a91628b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:fa9e201d53ac4a3d17a7b3ec98227665b75c50ee6326d258cbb5be731e241667