Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.10-debian-fips-dev, 9.10-debian13-fips-dev, 9.10-fips-dev, 9.10.1-debian-fips-dev, 9.10.1-debian13-fips-dev, 9.10.1-fips-dev

Index digest:

sha256:dc762d0b32df1240b2f2455624318f14d5469b1efdc2ca56242b9126a13cba96

Manifest digest:

sha256:26f2dcd92c382c680ffaff3271b80c5666256f1db3a4b3c6b2c44b6102fc9984

Size

134.62 MB

Last pushed

13 hours ago

Vulnerabilities

0
5
3
15
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:486eb193d5bc964fc7e7cffc83e33c10fd3bb4969e5c81c90b342b9a5425fed7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:bc398ff4d035b9a751d5e5a286033d076dc09f89b7722df0c63e7e387558ce25
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/solr@sha256:c5f1fd7d90f574757b5e366f64fdaf9cb18d6ca785fb4ae162db3fc88f81d6ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:f8f7f96cca54d6ba44e38181398d98f298f5c6cd433a5340c978bda34f4757b6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/solr@sha256:107e3771eca0ebaca44cd37a08bdcdcf68326383419d0f40b5e20a1e6f4c49af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:3faffa6ada5ecbefe8e0e0ccf41602ef6dd0bad5b5d9005f5a31a9bc07c07bbe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:4e5a874a0fa1f4e6961aa95140b0dad6ec474b7cb431ced1a64b729b40d6b133
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:aebcba299fc0c3c156835fcc65ab9405fc621ce7ed697a0f735220d98e745a59
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:b162904370a3ffff421e6f69682f47d6dbb26a06a1298a4b21de9025f4629268
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:3865541b503111b4e0a9d2a1eb9aa898e5410e3014153e8e9d3a354153f8c0e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:31d92d9e8d6107960a46d684c6b5c6a32ee5197cd6051093f223dd395982036f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:1b74dd2abf55257735c7899135ab9d3449a3df31497d74940f2b84ea6c41f219
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:fcbc4f7212657736cf6c4b2453d160e2614a6aceb2a44521464972f4f22329b8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:8000c5f0e447dce9e1ff62e0a3d5e5a413a1d2d87ce5e7a39bd02348b22363d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:97d2c5c587c0e43e7c6afa623d0e5e5ba620ce1cec955afc952094313a7d6622
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:7ffa13d63961ae00da163ad9e065b8345a1b79383e9c16fc83fdb63c222d1e07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:89298035bdd10be8b6cbe0f73a8261f6c2e3ade6230a327580b1cca8703bc71e