Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (lein)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-lein, 1-alpine3.23-lein, 1.12-alpine-lein, 1.12-alpine3.23-lein, 1.12.6-alpine-lein, 1.12.6-alpine3.23-lein

Index digest:

sha256:f1f8ef944a1f8fea752cee930b5742ed94ec93fc02273410b12adc1009e2ebcd

Manifest digest:

sha256:d21c7ca23137f37caee94e3937c6df16bed496645ab8cddd7f78a7b16f5422d6

Size

60.35 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-lein

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-lein --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:bb0a6ffde45314b7737b5960d78d58f430fd697cacf583d2ea29a71fa1b7c151
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:5d575a1d45984593182ec152b14934b0f2edfa87eb6185e5c7236982cecd670d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:e77d84998c3d5458fc00bcf37a061bda606228e143d293d4f059b6b22c2766e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:5093f4f6c5b9c2e278df8db7e99065a696257f8cd88b256bae86e2ea0637e04d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:cde932503d17f43f82ccca35cf88c497bde5cdb4d66d348e94cb6629401f5259
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:448eafeafd35c9f36d32a2673b5a9c31e54e98f72b764435acba5d7ab00c17d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:7910c6775977b51ffe950d051880d4b7c6a0d4d66271e00e052ff1875bdc3ac5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:22c9f50ebf4f123d2a749f223271ad960aa28dd24cd74483c77e45d8fc246006
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:9198ceffcffa647aa41a94bce7e35e4652183eb01de809eafcadfcd22c6e3887
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:01a346fcd9fd7b5e83389d89099e4037c316c9bb269e99abfe8e8af0d0ab433c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:277cf4003248783d3dafe7c6b9de5247a38c205788463c58df1d607e1cab40da
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:0f847fcde3b4d5dae48bc77e18eb28fa6a4adbf75ccf53cd2cbe8d7ccdbaee83
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:02a7782b5af1a013d9369a4f0e166443cbd624f8428060e5049a81f552a70345
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:8bb902f83ee0f39c00cfe034ff1d7b07dd5c378e953edc1cb21a7ad0dbbe54b0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:e949f80e6ed64df433af5993e24a6573ec01263ea525d7c1b6be71808da949eb