Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

37.0-debian-fips, 37.0-debian13-fips, 37.0-fips, 37.0.0-debian-fips, 37.0.0-debian13-fips, 37.0.0-fips

Index digest:

sha256:8a9c604fb25bf8d263079f4273a8ad93a467f1d7e16f320106441d5ae5283baf

Manifest digest:

sha256:6ef4e6c20088750cef280418b435ebd2b7239e50513776e66f131b391c8a982a

Size

1.00 GB

Last pushed

2 hours ago

Vulnerabilities

3
21
27
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:8e8ce07f76747f367c014aff56d17488325b29cc2c5b2615a83384f5bba7844e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:addc8aeca3863b525e40ad1685e225121039551591fd3d0bf7eff7872001bba3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:172e27eb40bd3cc0b99e313fcf779d98ad3087ce31d90d465a4cdcbf3db9f959
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:080ba5fbf2a15ab1c95f9cb59dc257d4485021922059e2392852215aa7c9f1b0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:037d5f6b933bd8707b788cd5f1b989f94acb9853fe25563c54fc1e60aa958be0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:770f6a5d763f2ea55bf39510763184af2343a738bac9baf3bbe2bfae2302c526
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:8aaf284cf21f01634205b1819db9022e322f377215c6379afbbca27caf2e9fde
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:31d7fc0c91e662b118761bab421fbeb615465735f7412964f43a1b3bd44d9ce3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:8c5732822052038a5282017c792b3e200b5720bda43e15486c64004b2aa66f94
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:cdfef979b7db09c483eac4aee4ce87e18f37e43de6e019a7987c0721ca09d57e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:293e2dd0b99ce9c36a71d3dcc6a27e8341a79c76a173ed33a0cd21583bf9a1f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:1b4b6194121d76991da4dd1133274c7d23c387b3913c8d108533e778f061d870
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:c4fdd5a994dd77f9c626084677fe1382525cbb79251dee5b5fb42a20d6939177
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:d49f61c8e59f4ed1eb7eefdb87f890d8caa888e9a6eae276c40d28db50944983
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:d3f5f87e688b10b3d8b19515e83e2e6586f4be2e8dadcdf6d8535283d03396f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:d497dc2f6c3e50bf9768a15455fe38d98add6c95bde3db93f25415a0b6ec1131
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:34eab5b530524e2935536d79e90bc5a7b6742e94dc44e7939297a9964cb7c017