Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 10.0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips, 10-debian13-fips, 10-fips, 10.0-debian-fips, 10.0-debian13-fips, 10.0-fips, 10.0.0-debian-fips, 10.0.0-debian13-fips, 10.0.0-fips

Index digest:

sha256:5364c68121269ace7d5834e086ff6d085b88a146939e4997e750651b1d37c592

Manifest digest:

sha256:050fca7f246fc0c7c93b268edfc2cbbe4d07ba77b896d7c3e720b572c12ee1be

Size

135.58 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
9
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:10-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:0b002b4f364292010e146755576ca41c418a402affe5f5ae3ef266ee83d52298
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:29718b3408997a401e38ef9ac0cd5aa7e4f6148f549a6a27da8975f01ecf304e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/solr@sha256:429c24a3ad4294b4ecedf1951db7fc22446f568a43a2a8ada37cb020bbce1df5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:58eb5a1ceab2720e178210b275ca45123c11eb8fde7db7abba9e76396a8ef25d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/solr@sha256:d20d69b70c1dc84eeb907176a1a36360bbfb715814d3f0fe00ad8892d88a528d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:d9fbb829858cc419aa084530c30e235947157c4dcaa3775800a77a6025bce200
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:817a98665405b15db3acc9405ab829dfdd0ab7ecd1048baf8866bdb6ed05641b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:a39378645d889a02dc8f865ea640e19e0d5f8140359b2466d25497c6b07e6cfa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:a1d5b6ba9686bce23274282ab56df6ad8aaec06536112b0e8ffe0963fcdd30b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:4577332a691d4fa486e986a600b0421f070d92612fc20d3893cc6d327b378090
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:c8bd07faf05e15ebc39ce9be745e3aa6260b0cabeb2d489e57c3b3e8ca88d001
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:43eb75c52160f6d683bd60a87fc5c4d74568095636a8b7064f93cc284ca147cf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:6af6fc4489338ab1f9050bfa6dd5ac172457179043d2f9664fd8bdd4830228e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:c348edde295a708d6343771a0aeac3b461ed52fdd2270fe67194fd6c9aeba1d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:3338ef638ca73b3fd98c21aa655e914f17cbd151bb7c2aba7d059ec2e352e104
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:0bf73ed5c7cf0ffc344bf8470ce23f85714a025eac3945500b164a392da1278b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:28195a970791295db8dffaabc4f3ef3ff1fe1851a743cf851868cf888c8eee92