Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.12-alpine-dev, 1.12-alpine3.23-dev, 1.12.6-alpine-dev, 1.12.6-alpine3.23-dev

Index digest:

sha256:cfd16d00b53a1c12dda4571b1e6093971d634bff46ce6b10a0bd656081ea1b76

Manifest digest:

sha256:650fc60f5765d472a5e9837e2912bafc5833184e324a142bdc5418a67f1ae2b8

Size

74.48 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:677dfc492514ff594aa30628b0083148d2e95f30f1e8ccf83a8b8be3226c3807
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:c6c186dcfc5838980495be4bfc9e28520d9fc62e82cfb7bca44f938973e930d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:0347fd59588cb4f7d987dec2608a65dd5440c94c4ba4f6894d3699596c284147
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:8641397aa8190f0bab86b4f45b7f4cd264cb04fc172db3f146ca3b8bc1fad345
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:c3bbac25bda7c2c72d214b27d53a3d11cc7c01dc1339062f3b6ed921c4c44f04
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:47a46cc461dbebf81f25903e9989df271e3b4c685bf57c5c7a792448847d6446
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:b69f4f9adb48d81acb338e334c1287cf228c1d8908af9578ce3964f585e4b98e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:c888f20d29010ce468a0d36f479999a49b748f55d2983975ff43001845bf11c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:a01471efe8cb5b635dacc2a9330ed9d06f033456c915f2c9ff3e38fbfaf8d9ce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:d876875be5a3211ad323c6fd1bb88dfd7b99cc20af586cb7e8ad9507f522da95
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:c04367f581aa56c3a21f5d19b5aeb181e805b0978e88deceaa302470dec4c26b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:5fac5c8dfdab153f8d2f40c68f4b0ef3598bb1684aac7db18e372d9b6936fa06
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:6b80f7abfca5633cc016a6e1871f2f72701ced9434244de05da99895e46bedb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:c20bfceb45d892637f4d0532bc8afb045dc57393059cfb04673c6ad2e096cf99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:1a0f2da0718ca2ad8951a8b112e1e480f418332498f4ea35c921e6d6a2cda79a