Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.12-alpine-dev, 1.12-alpine3.23-dev, 1.12.6-alpine-dev, 1.12.6-alpine3.23-dev

Index digest:

sha256:62f4c325993d98f7c6374e7a3cfcea8aae5e525ee79979416d5a7f2d7d6a24f6

Manifest digest:

sha256:8ac26d0907543f44083fc481c10f92f08758e55567b75bb68c1db92fb9126930

Size

74.47 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:0efd39fc00ab35eb300aa6c8f44e5a981d766c5d072db03c3f8ae955aa905be4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:84cb9604f6d382d68511e73ddbf11805002a4a79b028791505f615107a29da2e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:b9e92f0f146a475f3871199fc6612b7fd06d5b3ef3ce63bab4bd0d43f2230ab4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:412e0232324a4a7d065b11362d1486d28b4156fc15b1b9791da8520efdd955b2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:f89c3d8fa260888651c0fa1f9600066111455f3aff1ee7ea67d06d7c908885ba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:b3c5019047fd34cb6ca2fd61337480f75a93086e1e57deca9eadf4798934d2f2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:c2b0b033b33408d19fd658da3c9d481b39ee5b1cbecf031e56619016301a2a87
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:f211c39b1477d635426f1fbfa86dfc84b6b0fd720231daf9bf59d921da20087a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:850f22bd62540ae0a976b241b5576d4975bbd425d963996a3f837e3b00107842
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:698fdb8cc839d454a7e5aeab242ac399abaec1876e3aab8b34bb5d6aabda98fc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:bce3a89c5b5ca253dea3e43aab215922c99c6e77a76991f432c04cc608288eea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:e193c251893fe216b69fd1f5b0ad6433460e1609ff098faadf8ef87f4a398c2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:361dbebefe7362c83c9e2fb237cc06a0b8b7a10661bf0f446dab0fa557019bf5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:2b67a375c6090e0cbff7327acd03978688e08f2d495bd141801ccc3b9edadbfb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:9ed7f9014953f518b29c72de56570d2a5170f197364534801669a48d3bb1dc35