Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (lein, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-lein-fips, 1-alpine3.23-lein-fips, 1.12-alpine-lein-fips, 1.12-alpine3.23-lein-fips, 1.12.6-alpine-lein-fips, 1.12.6-alpine3.23-lein-fips

Index digest:

sha256:2a0797efb84ac1a966fd3dfadd1be24a3e10260ac9add71395d863769ef710bb

Manifest digest:

sha256:c92b306cccfe76660be6c5bfc469acc2f509b8e290c62a8560862b7dd7aa4801

Size

62.08 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-lein-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-lein-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:540d024cb66ff0d97942db8db78a08b0896546e12ab791a04d06b3b093c4a470
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:50d08118a6987c7ca3a61a3f63c8afd35a57694918da9339d7a60aa69097d71f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:bd7fdc93375f14507bfa665502e904481bec3b17cbe5bdec63f8a859dc6749e9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:047fb9511fb17a064812909c58c72c183114c9639d0554f6dea93fa2cc9ef364
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:02f725aa446c2debad811eec3702d2426ed56ba80f4d42a67099558e010e6a8f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:04152a6a21e03b988617920582557268f00927870f64feeac08a96a279988572
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:21cca86a296c31fb5f25cd07d71b216512351bb46c215d36c32965544aa8bd38
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:5a676669502340ea3bf788e84910be0ff5a2269bab5c50186c59f4e6d4ec3deb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:a132753a8f52f063981d249372ede846eb735d1a922640bc7a8a88a364ccfcd0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:a3ac836a1578e8864846aca3070db280e738a5c54189ee57ecae0ac33123e450
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:68b664c10c96ec96c526566c7b0a374309975beddeec127be2337fb340c5f45e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:063e05317229709512be60731defecd1a2fdb5676fdc7c37e649b65bfaf4dbc1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:66869795b8f86db509944e80762bdc36de85ca015587f8c262d34d48be1a81b8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:2382b87c477a18d50707433f2852cc9af9470a699dddd24136fb7521f8a3309b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:6f46e0749a7792613b32ff2b81ad986f21f73ecabfb675e4389e662b2546e34f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:7caecf0386f1621b4de34f20d31f997838994aad028913712fc7050dffb609ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:2aa76f6a5e37548adaf7a133a900873c20d0c6726003425216e8011c4ce131ff