Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 36.x

CIS
linux/amd64
debian 13
Tags:

36, 36-debian, 36-debian13, 36.0, 36.0-debian, 36.0-debian13, 36.0.0, 36.0.0-debian, 36.0.0-debian13

Index digest:

sha256:25739bc9a48227f56198c4d4addf788b5f1d625a8a967d20004d75f3b41307cb

Manifest digest:

sha256:01bb2cd60557fcaa9c51b134e0afa9f934523dacec59d0295abd0dc1357cd2f6

Size

1003.72 MB

Last pushed

3 hours ago

Vulnerabilities

4
28
33
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:36

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:36 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:e59cd63ad06b99c60bd21a0a04cd21fd29068c99f680db8001b6cee099c2ef50
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:d0962106b85946f1a9d6118061427afdfedbe5fd689c8536b27cfcc80e36950f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:8e97640ac7476882775624512293fddb75d86501a3c7bd04b21d2b596537ead8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:15673cfa943991d8647722c80a320e027758904a0b1364999b6992a411f9d02e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:ee21e04575a80e47618aac51c46c8b800cf3ff8e02cc1800e8bfb206e65cd6b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:262c43cf4221195ba0cb522e90cea7dfefef8d255a6ac02617f07a252b857df7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:bee0031e46e6d4ed9fd60f417073ad12a416d9510c5501ef23dd90b1a2c9e53e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:8dd8f5ff07e731afc06591022d67053b3cf2ee8f9a8c5c365577d6cf9a6a2645
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:f07053294230713cfd713ce906e4d323f289fb2169f38555a5ba672c8dfa0f13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:8444978bee6dff4ee2738c73c43fde16ce7c20d5cbd99a9022ec6409771072b8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:859b99d66569de471cd992fc98ef53b390fbf30ea8dc23e976507c32f10d9cb3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:3c844e61a58f553d7cc6974c8b9a5859de422ea3a1ca617df8af75606b8b8325
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:8392780672c5e10049f94603589878129c820b543a85bb4955c68208eb9cd2fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:a971aae44c29c234058aff760ef0a0a6c930cc4c0cdd0bbe136cd8908b8b6285
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:0cf32d77b8fdc93fbaea951e3553dc404e5ab537b2ada17d87669f7b24432d1d