Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (lein, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-lein-fips-dev, 1-alpine3.23-lein-fips-dev, 1.12-alpine-lein-fips-dev, 1.12-alpine3.23-lein-fips-dev, 1.12.6-alpine-lein-fips-dev, 1.12.6-alpine3.23-lein-fips-dev

Index digest:

sha256:3221293cd7194411459d1650fd2b87c32bd6fabda101638a42e38ce17d208698

Manifest digest:

sha256:a5212b3aeb359982702e39218cb6062de49d43f3bc5cbd985fa7e8f690034bb6

Size

62.31 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-lein-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-lein-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:ebdb12791cbe7fdc412003520e2d6ca062bceb1127c72b861a1ae48ed6362831
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:1fd7992be9ec80eab013bf3104a0e19f4758c928fd48505ef0b800674f45a984
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:fdf410e33c7fcccc2bc398725498328d8f35de90a736f1e16cd1c7d3a38b70b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:4e9cca5b74e261ca0fc65d1304fb71a15d0ea0134a3cee935982dc0cd3d416e9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:3b4af49a547305f136e5e078bd627af62e593e1f51b065ba7f228155eb51b4e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:761b8db48730276d3638e2c70a191aedab7cd55456bece6115fb57c90eb6732c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:3d284b84cd7bed18d7348c30f31d9061979830172734b32c597faae3726ebe15
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:5a2786be9cb39df26d0607727a75a5f732db9f59beea324354ba828bd441cee2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:4d88a5a689dd3fbc0b0d6150621faef2abe3f7823cb4b4ae648d6421909b1b8a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:1567da452fbcb6bf7884f28173a6715f07b5cd5212282699df16dd3a50a66ec7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:cd5e5ea143f76d5cab07cd9c7f85716810b5956147558384b19322a355087e49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:bf19ba3a98d08a2bfc00f780147697d72e91f24aa13ca2336f28f56ab3236ac6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:7de94555dbc1631bf2972a88cf864924d61fbbb99412a0a0e8f26569d9c0ee27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:14779122c95e5e21f10ff2241eb8f8b2f32faa84bdaa3b7c57bc57e16e72b81a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:3f9f3999f9bfed04c98952ecf4120b60fc232716a018eb6b12c37ce1ea32c088
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:4cf75ee3f44b5b0882c2e9dfece57a079e99a81b63ef0df291f7ec0b363bc3be
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:6f3266243180f45f280a912d72d4a0e5b2f5ce31e172d6fd84c94c6d652975e0