Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.10-debian-fips-dev, 9.10-debian13-fips-dev, 9.10-fips-dev, 9.10.1-debian-fips-dev, 9.10.1-debian13-fips-dev, 9.10.1-fips-dev

Index digest:

sha256:5ad3bd2411a3421051eb6f429e4b7c6a73d1ae2783e8e5fcfe6b8256767b2df0

Manifest digest:

sha256:ed8aabdf42dd86dbfac5bf7b1d24f1fa7c4f0b845b46c12c0d46704ce49eff82

Size

134.61 MB

Last pushed

2 hours ago

Vulnerabilities

0
4
2
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:a2cd17384558dcf0bc74149d6965699b383125e1634804157fcfcb625e0b3777
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:7e7902be0dbcb531f4227f0fbab5a15398457fd276c540d3e9d2921201ce7b41
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/solr@sha256:61cc9706ca2f18ba7ad27e33330b710ad2cc1b3eda2f4e8bbb9cca578c66b1b9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:798130ae22eaed6ad70b37ee9f94b17a074649b8d4832e66b12f1938f9d893df
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/solr@sha256:6a77c6f69de9860bb9f07bfea69fcd13d01dd91ab4358cbf7ae383cd1e3a780f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:11b5d1d4e04985ddc451b688dcf3ce0d58804d21eb888c0adfd59a8f0fc87f22
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:f66de7b1810a741400f31c33399815deabbdbf2e07baff2ee7120af0ea4baaa8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:7920aa497a52ea264e17904e55486a7f80c8bd491787892fb55e5a002438ff4b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:17ab0aad94b326e63730fb2eaa4b92df77422c78bd0556383fe7504b79845b31
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:91ddeb44f6a003b082f98fe86a2982f079565c54035597ebfbdbe0b38a398510
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:f93b7cca603a986cbea6440e3fe8fbf5c02085771c92367a9306c8f1f561317f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:c43e906a84901d728efb7104982683d0e24cb1a5d897b5f159f59929f72ecc72
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:ba94855918adf7362d7ead56e521fc14ef0cbe31c4c9e5b5d66a326883176c2f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:694b1596cc362f7f5c747f4f386ec7ad6af95ae0938a7eec28c314375670647a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:9c5134640de254c5c2a321ec32205f31d3f4d4496a24c9a88dd32864b8d4e487
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:44459dcdb8752d0807f5841349d4c367c7116ab2cd9232ac07ebaa38abbaef7c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:2318730d8506fa1c9cb6bfaf51d30639ed2dde36968ae4d5e0ac0e3695e20df8