dhi.io/sonarqube
26, 26-debian, 26-debian13, 26.8, 26.8-debian, 26.8-debian13, 26.8.0, 26.8.0-debian, 26.8.0-debian13
sha256:1900c7d1f1eb4b06f2f1b6a21f2c9fdce35297739d83d9252859b80e28097e9a
Manifest digest:sha256:17ed375f512a820fa34b858d9ec52671a111b246a23fbe80d026512d0dcba9cf
Size
1.00 GB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/sonarqube:262. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/sonarqube:26 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/sonarqube@sha256:1fc49fec14cba2f28b7fc8b6ef57e248fbce7ab1993f84425cc3d353d8a3b522 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/sonarqube@sha256:3a2d1c4a1b77a5a54fdc8d96c842a9fdcf075f8f061da2dd2a562666d62cf297 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/sonarqube@sha256:555ce2ba1f3fc8e7acfb81c8e1043635a975125f6673ec1742ccfabc3fb61a50 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/sonarqube@sha256:cefcf7b38f7a7dad541d269c528c4b369cfc2e8548202810e16390ef9a735a24 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/sonarqube@sha256:41ecfc8cc4b73341fbe74a14ead17938453b74d69edfcc64d9c0a0d45c3dd0ea |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/sonarqube@sha256:9261fd88b93ead6c09feb10a9503e10f67828253db8142782196f451221e3fb8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/sonarqube@sha256:46b2705baf7cfac38683445309b9dcee734d988887558e0c686a8bb59ff17d90 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/sonarqube@sha256:a11c9a42775002eae4814e8a64577b7048359bdee0cc7a11a5ce0ea4b57a12b5 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/sonarqube@sha256:bc85f0bd564c50269409991df7b5f07567fc705d9aa967c106e9f289f5ca6429 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/sonarqube@sha256:eec631d13a727c5cb2e4af6746e6a07716d043b40352200079912fc8ba2d7978 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/sonarqube@sha256:0a9252833cc23be156757e717eb3b61f1c6bb3eeb5926820a2e20a32681e3ff4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/sonarqube@sha256:1b23b9f12354c5dde17224d7f50a22c059e018af7af666dbe735ede0fc8c2a04 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/sonarqube@sha256:b6603c0e36fc9152ce19fc52b2e70cfcf1f15022dcb2ade709db2fd4c5f768be |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/sonarqube@sha256:736a87e5f27d36d1c50fd9f26fe1094b5c20320422164c6939b3770a6eb79931 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/sonarqube@sha256:908933a0f8f602c8d56681df25f58be076eda3df39a142ffc8cd9f4f68a5b400 |