Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips, 1-alpine3.23-fips, 1.12-alpine-fips, 1.12-alpine3.23-fips, 1.12.6-alpine-fips, 1.12.6-alpine3.23-fips

Index digest:

sha256:5de85740d55d0fc6cd1318a0d213d561d649da6ec5a57f148bc66fe0446515df

Manifest digest:

sha256:9e8f2cb61059c28f45f8f889a483cdc1a670ca7d5270cdb96764d21b1454d362

Size

75.58 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:be2b98e30339a4ea3af0d7eed738f582e6b8aea57fe29e31eb2ac85e0a91d511
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:4f52eb59dc55cfb52d932ce63f4a2bad4390c6421f7b6c0b19423d6088c94662
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:b196ab384bb6e2a76a9f3a813474260d66f9443278ff42c5309fffd5b55f1bcc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:165a038069a0f1d8f9805eea8dfc1772ee6df8cd35ce815962ecc09b992293d1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:44ca77e5c3ba487712c64b24ea5d026cb7d4f4785618b91b93309692463c0ac2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:0bba6b7c7208895d435b6240f48a067665236123950e04509fa053d79173c360
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:a00d04b797475e6654bce3f0375f8b8a3bf891c71ce7116abed9c10b809059c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:954c1060b0b4d62ee7a5092ff644e47177c240df22e150ccdd4a81e3827b6561
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:898eb24cc6aa58f77cd5a0f9ec0f250ab3144676dd286fb83615641ee066f57c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:7ed8594a9e0e38cfb99922a2b6ecf81962da2156d633c75525c7029843f1923b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:bcbbd2fcb526003b674a13f9835baf0f53071f917c47e0405c19544ee40eca28
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:6d5b1f7965dfc4fe6fc8b3bb39b7e51594b1b2baa6d447aef6ce3a22de5c705f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:32e1cee5817dcce451f1bfbe336fd547b1fd54ec55daf36d2d072316523f3f57
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:92c3d18c9dd483d96f26cbe0d3f7751f338bd20add23514581405485829f71bf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:e13bd8f4df7f7bcff91ce13c427ccc00b71fd2cfcc6151a62e20e800f287ffa7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:faf86046487071a8bc5a1926a3f19d643478a4142386f4107933cc8e764b9a67
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:439343c139b6639423960f47209f85238882f31c3db1741ea6999158e4386dc0