Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.12-alpine-fips-dev, 1.12-alpine3.23-fips-dev, 1.12.6-alpine-fips-dev, 1.12.6-alpine3.23-fips-dev

Index digest:

sha256:184ad33fa051a5a8ff5c529ca4c3ae9488036072175edc26b4dd203354c1b341

Manifest digest:

sha256:0facdf784be6295c47ac67279104ca169097eeaa48319c2a846ee07c92705828

Size

75.75 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:26397fb233d34ee27c51db72f447d4ac3034421e948f19ca56d2aa81f4d1582a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:40b77c6fc696df37517784ee99c517db64df28a312884f49f9d7835a904d2cf6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:24d318fe90963923d3e7338f4af0c8ed4069138dd90d78e026ac9731168f6500
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:42200be3424ae4b4abb223c4a1c3d4b7a1fdae6e55da3c02a03a093f1816ecd0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:fe20f1dd603683dcbf43070d2a3350150246a78e5fc46cc97f3c1c4636f293c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:02849e0e2cc1e6b0e142c0c0b479e5137df42320213e9b80914f6a4b1b54c0ca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:5db9f8ffb4568395c35ddecbc4745e2783bcd7f6b8084dc371ea7b9f9b1e9357
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:233d4fd91e175227db910253e8fdd521696d8442e4d3b623dadd74354b45a888
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:078f449fa3082b1ff721f5c999e473e5d81981a3faff8e85c593ce02680e2253
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:692cb4e9b77a12ce5d206854f0450a183c15bb3a5180070ccf704b329618a07f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:6e47ea291088a09ef6b766b4321bb5b8c85053e30cf9b6ef129fb89cca426d72
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:414fd4216dff06077f73e54c67a413bad0b3788cd3d2c7f4a27cfb55be4d808d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:056b5ec021787272dcd9e9da3970a484452e36b2395737674028e03a172a38c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:78348a7658bc65f6957f0f0792a86cef17d8a5dafd8141658b20e7ca7deecae7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:e7e77b37ab59ea48f471a9d0eeaeff38ae5ce96fda18798053a17cd2c356277a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:7d8262514e4aff9696575ebe8c56a403f29580ee890377dc0f4a2d74811ca517
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:9e052406c0f4b9ae5a7b8fd80b555c17c07ae74c526fe4a858774fa607cf680c