dhi.io/druid
37.0-debian-fips, 37.0-debian13-fips, 37.0-fips, 37.0.0-debian-fips, 37.0.0-debian13-fips, 37.0.0-fips
sha256:ccb0ca8c18dda23817b335eaf23512918e666e5cd3bc585cc3df8c99223034a9
Manifest digest:sha256:d6a6a62091e2142179a1b76e39ca8ad8c0edfc415a3bf73730f89011131a56ea
Size
1.00 GB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/druid:37.0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/druid:37.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/druid@sha256:b988a3dc2ab9963781db71a569d2c9bd45afc8c820612bd3125f36dbf95665b8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/druid@sha256:758ef8021ebee84a2d0f2a4a3203622d22ab31f7a14a6b560388297f76e2e2bf |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/druid@sha256:cb0ec3fc1f8de384005c6f8833b13c1a845d4792c444443800b205fff933f2af |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/druid@sha256:7a2312661806befa4e145d76d39e952a5fca530cd7628a8f6ad22f17f1639472 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/druid@sha256:03f7c99d9a6f3573c04cbc216a3215bdfc2fef6366d43e430e70cb9c3e20347a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/druid@sha256:6f9ae4c9643eb6a014bd3442eed73ec65ce0207532e310cf0f078b2032e68ff5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/druid@sha256:f702d385d73d3aa758663f30a661d612eaa795ce1d3f513e29ed2c9493d7c6e0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/druid@sha256:d7a693898c615ed8e8bd76947f698d5df74fffc626e7e118930f93076b9a2ee5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/druid@sha256:37f6a6aee35746ad104a8c6290ef97d96f824706fdad3c0e2d4f9413028c468a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/druid@sha256:5814717dfb85166d12fc117a61a5af5711b453be36931f53ffe0fd33010f75c9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/druid@sha256:a86fb345661dcbabe510dbbca95b14d69ceb529e6c7721349b07d04c48eafe7e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/druid@sha256:dcb2ebc0241cee0f9ffb548db104df3cd22330d4c2658720f8f9d887ab6f1356 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/druid@sha256:f8aaec3e9063fdb8b7ae24dd3ab57cc1029c8fe1aa7fec0b83930374c218110b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/druid@sha256:4744089f8a0febd81e998a3ef90618e9e38b0f79dd879bc926ca1efd89b2bed9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/druid@sha256:5f4534d6fa953b4af7e2cd0d0936f6d5f3cee0a912a9a230ea7ee018565e3d05 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/druid@sha256:f5bba716ed91aa96033ca704cc88212758284251c4c496b8a1f7604c4cf13f49 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/druid@sha256:cce35caf453f1793cbf559453b93355d13e62ade2130ad38e5f1580cf874fe97 |