Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-tools-deps-fips-dev, 1-alpine3.23-tools-deps-fips-dev, 1.12-alpine-tools-deps-fips-dev, 1.12-alpine3.23-tools-deps-fips-dev, 1.12.6-alpine-tools-deps-fips-dev, 1.12.6-alpine3.23-tools-deps-fips-dev

Index digest:

sha256:70a8e3dd55f25424609996f6ecb69287e748fa2fcd8300aa9b6de7b339583dd5

Manifest digest:

sha256:90f02f5df57bd5a8c6e76a91a6d89f700b6ac130da7262afc339d26a0ab2eb77

Size

57.02 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-tools-deps-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-tools-deps-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:ed00c91c480b287a0ec5a1c985b4d4786ebdd61698ce915233592b9a90cfa1f5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:500d1c27863c4402322e7157fb72ff5bb5473e7359b6deed8f1dbab2e94499c8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:3043799c59c935402f01cdb13ad6c26551f3425388142ae46e2b39e1a151d734
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:8379566a10283097d1915e758953a0c5beeabab4d2c12fc6ad3cdb636c5ecca3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:18fcae290615d869b38cbf109bbe715d8ac3cf58894f0de064e41616052f35dd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:b3c6f954935ef59d0898cfe47030fc0327a0bfe2b6d1a5a3f21d23d29fa254ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:4baddafca70ec8edf23eef73d72057bbb0596ecad1211723228f891ae25d0439
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:ceb9841dc92ce85dc024071cba3563317ad899ce3933ed9f28b4d9ec0456a75b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:b1ff9e589fb4740e10c40c18fa5c7e19c1400aaaab042da74151b6585d91ce58
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:e107efec488cdaf6e0b0cc6d9f32a2deefd8cce02fbf7fa8ff8a534fd05c766f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:58fedc7db6a7ae12e13a16886014cfe8407a5d6221b19da98722d2c4cb7c4885
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:230eba1f075787eaf239556c11dfa03e7dab8e47ccb19b87f7126b2e512fcd20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:3897064fa8fbb73b1b8615085e8df5a2c18acf9de57cf4ec0f5fef10a061604d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:e030abc85cfdd9d113778d5719702ec14b53e1f5028de5c4486327a124ac4921
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:c8995c627ffdbd58b415c28520ca0718a44383d0c4004cf2132075d706ab7570
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:b565f6d10e2af4dbb322ee75272ad2c9116eea111ba79a9b12b34914d288c4e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:d3ccf03b7318c7b8cc754bc80e21126d9fd89db48ce38452c912e574fb347180