dhi.io/solr
10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.0-debian-fips, 10.0.0-debian13-fips, 10.0.0-fips
sha256:5364c68121269ace7d5834e086ff6d085b88a146939e4997e750651b1d37c592
Manifest digest:sha256:050fca7f246fc0c7c93b268edfc2cbbe4d07ba77b896d7c3e720b572c12ee1be
Size
135.58 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/solr:10-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/solr:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/solr@sha256:0b002b4f364292010e146755576ca41c418a402affe5f5ae3ef266ee83d52298 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/solr@sha256:29718b3408997a401e38ef9ac0cd5aa7e4f6148f549a6a27da8975f01ecf304e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/solr@sha256:429c24a3ad4294b4ecedf1951db7fc22446f568a43a2a8ada37cb020bbce1df5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/solr@sha256:58eb5a1ceab2720e178210b275ca45123c11eb8fde7db7abba9e76396a8ef25d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/solr@sha256:d20d69b70c1dc84eeb907176a1a36360bbfb715814d3f0fe00ad8892d88a528d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/solr@sha256:d9fbb829858cc419aa084530c30e235947157c4dcaa3775800a77a6025bce200 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/solr@sha256:817a98665405b15db3acc9405ab829dfdd0ab7ecd1048baf8866bdb6ed05641b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/solr@sha256:a39378645d889a02dc8f865ea640e19e0d5f8140359b2466d25497c6b07e6cfa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/solr@sha256:a1d5b6ba9686bce23274282ab56df6ad8aaec06536112b0e8ffe0963fcdd30b0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/solr@sha256:4577332a691d4fa486e986a600b0421f070d92612fc20d3893cc6d327b378090 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/solr@sha256:c8bd07faf05e15ebc39ce9be745e3aa6260b0cabeb2d489e57c3b3e8ca88d001 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/solr@sha256:43eb75c52160f6d683bd60a87fc5c4d74568095636a8b7064f93cc284ca147cf |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/solr@sha256:6af6fc4489338ab1f9050bfa6dd5ac172457179043d2f9664fd8bdd4830228e2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/solr@sha256:c348edde295a708d6343771a0aeac3b461ed52fdd2270fe67194fd6c9aeba1d1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/solr@sha256:3338ef638ca73b3fd98c21aa655e914f17cbd151bb7c2aba7d059ec2e352e104 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/solr@sha256:0bf73ed5c7cf0ffc344bf8470ce23f85714a025eac3945500b164a392da1278b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/solr@sha256:28195a970791295db8dffaabc4f3ef3ff1fe1851a743cf851868cf888c8eee92 |