Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-dev, 1-alpine3.23-dev, 1.12-alpine-dev, 1.12-alpine3.23-dev, 1.12.6-alpine-dev, 1.12.6-alpine3.23-dev

Index digest:

sha256:d53f88e8283dc01de1bb3532d750ca49ef504050a8b1b9d1270ca4b90e6fae44

Manifest digest:

sha256:f139f88fe2a0f34d3d0eb96a9d16e9f2032a933bcb0e8026ad419e72e4482906

Size

74.48 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:a1f95604312112322ada2ff6df28e246b93369b31e9931e92d8aada731905ead
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:08e92d6b78c8eb2caec6150038fd68d44b16ae68a1982eac732b3e2ff0a3f301
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:222076ffd1c2faad6f249c4993d63d89025af25e6268f823c8a15f0a25217b4c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:aeffa6a47411bfa67f4a8e18aea34d06c714c2766e919aa66059709c9753216f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:b78a0c56e4fe22dff34b2c37c2c71a8d1777f0cdb4e1aa62da05a4deeaf2206e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:6c122570002a86c460ced4c3b3660cc0326336ccb6825e2c2c26b2d6b2bd89e9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:c049f50332d85ed91ff4aa05f53ef5356ad1aa9053922a0139be9a0dece0733d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:236768cb0fc658851b7f33fc45146fae179966c9cfe6a06f22dde74a7ffd7a49
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:2fe21f1186ac60e5e17acbc2cec7bdf795b317a7de86ac8e068f21f87eca184e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:0c00ab636fbf3f41d79ffe6c1128941bbd384b39180c70baf5b679abbd791f92
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:57bfa0d220ed2f9d2649eb27efad6b53cfd94895441190a09be8dc1a9eb6caa8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:23ba28129037b0f428c49fcb19eac3d5f2c7ff5a8fceb3900de32b358f2d55f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:97a5f148c29af82ada5c8cc8e492abb475ef60fcdc5738816646d418c1c9448e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:2980dda77c1f8f1dfa947c6ee6aefa5d360d9bc9ff080bea26a4288078de88c2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:78fb58fe92e8197462de53b4b6ef9e720dba840b7a242d981def25cea68fef43