Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (lein)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-lein, 1-alpine3.23-lein, 1.12-alpine-lein, 1.12-alpine3.23-lein, 1.12.6-alpine-lein, 1.12.6-alpine3.23-lein

Index digest:

sha256:a6bd7f4159a7f163bc2ea1b46ed2004d64daec1c67941a295befc824a73a67ef

Manifest digest:

sha256:8a247b0400f21365d06a87d5a464db8719bacc6f51dbf5abb8b93c2ac98cd156

Size

60.35 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-lein

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-lein --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:37a872963cbaa2482b4556a09fac5c20ffa770c67c9c9bf1f73806f228f10700
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:8620679973de661ea0b4c5c6abcf1b5cc34bddd7604e607786de005e08c03614
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:50282a4ca3953a4f1cfd2779ac6db7ce02ec2452289dbcbfedc0bd65f60b4cae
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:a7da6b170f8af283a04d6607270ad8e87d9a91007038cc23065863f000c6e646
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:295f382d2a59faa96cb6a281431bcceb9af6446a2af2ed7460b615d34e7c6b52
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:17f2dfdcce7f38192527265dcd70db6ada4c81fc8a5152b385e1d4ed69585072
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:8705555ad76be6a47e0dc593d581a19c9f50d971964a5d2557c11d17da482e4f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:959b44e840263a20d4e05e9bdb187079c8773cbc5a3c3f06644ee6f16e892405
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:5d4b5abb9a64a52cd84bc43a9c5f61364fa85099839e9296bbe5b99c9d57e531
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:6897d61ce17f525d4bde326a252d36a735f423bacb0e49d6f665c3b1e1b73c07
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:9bafaab364ea04d8c79f9afb7d18b015e5017e7be6fda5b5f03534005272986d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:b58c8e1e831dfd5174146758e6ebbe98df0dfbb7b7f262c9d278852c8f7a44fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:b30350370cf675914dcce339aab08147bcf6ab24e6bfca95768b0b975aa3fb0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:5059f5daa633c7d344c9a599007b889d544a51fb979f6ec49eed1260de963954
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:4d2c40b12594d5555981dacdd452e9c484fe6771c80580ca7e6e25be24caa922