Sign inSign up
Apache Druid

dhi.io/druid

Apache Druid 37.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

37.0-debian-fips, 37.0-debian13-fips, 37.0-fips, 37.0.0-debian-fips, 37.0.0-debian13-fips, 37.0.0-fips

Index digest:

sha256:ccb0ca8c18dda23817b335eaf23512918e666e5cd3bc585cc3df8c99223034a9

Manifest digest:

sha256:d6a6a62091e2142179a1b76e39ca8ad8c0edfc415a3bf73730f89011131a56ea

Size

1.00 GB

Last pushed

1 day ago

Vulnerabilities

3
21
27
6
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/druid:37.0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/druid:37.0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/druid@sha256:b988a3dc2ab9963781db71a569d2c9bd45afc8c820612bd3125f36dbf95665b8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/druid@sha256:758ef8021ebee84a2d0f2a4a3203622d22ab31f7a14a6b560388297f76e2e2bf
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/druid@sha256:cb0ec3fc1f8de384005c6f8833b13c1a845d4792c444443800b205fff933f2af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/druid@sha256:7a2312661806befa4e145d76d39e952a5fca530cd7628a8f6ad22f17f1639472
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/druid@sha256:03f7c99d9a6f3573c04cbc216a3215bdfc2fef6366d43e430e70cb9c3e20347a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/druid@sha256:6f9ae4c9643eb6a014bd3442eed73ec65ce0207532e310cf0f078b2032e68ff5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/druid@sha256:f702d385d73d3aa758663f30a661d612eaa795ce1d3f513e29ed2c9493d7c6e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/druid@sha256:d7a693898c615ed8e8bd76947f698d5df74fffc626e7e118930f93076b9a2ee5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/druid@sha256:37f6a6aee35746ad104a8c6290ef97d96f824706fdad3c0e2d4f9413028c468a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/druid@sha256:5814717dfb85166d12fc117a61a5af5711b453be36931f53ffe0fd33010f75c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/druid@sha256:a86fb345661dcbabe510dbbca95b14d69ceb529e6c7721349b07d04c48eafe7e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/druid@sha256:dcb2ebc0241cee0f9ffb548db104df3cd22330d4c2658720f8f9d887ab6f1356
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/druid@sha256:f8aaec3e9063fdb8b7ae24dd3ab57cc1029c8fe1aa7fec0b83930374c218110b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/druid@sha256:4744089f8a0febd81e998a3ef90618e9e38b0f79dd879bc926ca1efd89b2bed9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/druid@sha256:5f4534d6fa953b4af7e2cd0d0936f6d5f3cee0a912a9a230ea7ee018565e3d05
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/druid@sha256:f5bba716ed91aa96033ca704cc88212758284251c4c496b8a1f7604c4cf13f49
SPDX SBOMhttps://spdx.dev/Documentdhi.io/druid@sha256:cce35caf453f1793cbf559453b93355d13e62ade2130ad38e5f1580cf874fe97