Sign inSign up
Apache Solr

dhi.io/solr

Apache Solr 9.10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

9-debian-fips-dev, 9-debian13-fips-dev, 9-fips-dev, 9.10-debian-fips-dev, 9.10-debian13-fips-dev, 9.10-fips-dev, 9.10.1-debian-fips-dev, 9.10.1-debian13-fips-dev, 9.10.1-fips-dev

Index digest:

sha256:273336e09ea6ace8ded96c32bf628312e1a1001ff81e4be710322eeb8e44abfe

Manifest digest:

sha256:f53f2a959948da77ed00f652dd69a40e2deb315d45483f5bd3e0c74ba1f27d81

Size

134.61 MB

Last pushed

2 hours ago

Vulnerabilities

0
4
2
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/solr:9-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/solr:9-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/solr@sha256:255d3876e5be4bb9c98b47cd1a40d16fab73620775b831b75f41b0e51da9419e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/solr@sha256:d4acbf9b0b4f258dff8e69298f6256caeb43d783b4060d4a7b0968c762891c1e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/solr@sha256:df755d6edccfec4d5790c7977b0ea12f91495330be6d269d9bcad2329b1dfa0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/solr@sha256:0f11326e36f086b31af3d47b541a48dd001634bbb6e8667a92e96d3fe73138f2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/solr@sha256:f1ed201b601297c146e82c338fd56946d8342801e7356210b471ae421f45b767
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/solr@sha256:e011a65ebaf7a2768371315efe85e88731387266f6df2e6780c732f0a358bd2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/solr@sha256:3021e6cf549907b7cfcf2835735f9bd3ee6830c141fa83797c75b554015fcd5b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/solr@sha256:6adf2e9bd03877a18778c2a2b54844d4ca4d5ce22a89830173acae38c8d317b4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/solr@sha256:1d731723433764ce73a390ffde12ab92ea7e292789493ce5e36bc42fb953f37f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/solr@sha256:bf237894adf42645451464c4575979c0ff6f537709d1fd20d5927d6b192ad9a6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/solr@sha256:1080f8983b811916cfed06c65abc2ed6a30bc70b8c52c86690f8f9b1085d1ee5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/solr@sha256:c945176f8dd8798314d47f9e52d8c576faa95828d6d93c26abb63cda349b0189
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/solr@sha256:ab91aeef677b948702af991a4940ae0bf9d5a9802e9fd8662ad03323b349cb56
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/solr@sha256:e532ea09779b57a6b637c5e4307d11f2a9fe29c7836d1d361c59a029afa599ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/solr@sha256:62fd6538e32b76ecc9ba9e49ad97c0196a4b2c5148d5e777847b50c472109547
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/solr@sha256:bca560e48524176fe6560b71bf1fdbfd2e07e359829122bec840ff13fc510bdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/solr@sha256:43ec4f3cf53c25cd57c6b3df75cfe120e4530086766589697b24659b906bdcec