Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-tools-deps-fips, 1-alpine3.23-tools-deps-fips, 1.12-alpine-tools-deps-fips, 1.12-alpine3.23-tools-deps-fips, 1.12.6-alpine-tools-deps-fips, 1.12.6-alpine3.23-tools-deps-fips

Index digest:

sha256:5b1f1902627aa2659924aa4f282c1d23a59e8a16108c52e24fe368fb999dd162

Manifest digest:

sha256:52895f5dacf4b7a20a88e53fb50e746bb61d526a6693528a9a96e827ef47ddb0

Size

56.79 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:ed4baea5bf1a68f92f7253f84811a2eae7c89d633dcb5696d4a87c14a2dd76ee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:60a45b2a81e16df55ab2c11b051c69f5e4cfb55b263f65be114b7a12c76631fc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:76def543ef50435f22e7f48fe0a3a636118f31268e9adf1330b0b5dce49929f1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:3168bb50534a6ddac2eb6e9de4ad8076b7e113b0d0b7554a4ed9e77af1396348
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:c33f09142d8087f1109cae1630d2aaa5f77dc1582c2f615b9f24c8416055a56f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:39e3c9060b62f809cdda0420dd2643e84ab058acc0d50ef265a64b7d5b789965
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:0cea42389559aa5fb126f7034f54e9b6a1dcd034a0bb2f56699852c3d51c50d6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:c46511dbd3a5660b8568d6b20c902cb71810a462046de1bf6364883a9ce671e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:1a3dd757a94a88144e83129715f47bfbbb5fa57368a50ba1f0250a2a70604a59
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:1ae77c66ab6bce5b29e35d3b79f31d8f59097a3cd15aa6a744b928bd216b3ff5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:f5200012a955733c2c9a93336187cb673c448ffd69c2153bdfdf778a530d94e2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:28adde4ed1d64e2157f6594450ae8697ad781df706d116793525ab6755d40eb7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:7636fd5f7bee033dfcff95ecaa8efe632a203c004d029c4fce49b17915571cb3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:c98c68930b244ce77a62ca32f037493698498e8814b2ed900157100a2c88f35d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:353ebb56ecb04d7499b6ca3c78d0b6d642f879be690b2e71618eb8c171babdf2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:511d5cdf77b6575af922c0a08d4514a5ff276e2337fe64fb81f7ab0cd780a2c4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:2afc6076cf5bdf79e0845f3e20d652d9fcc6fb66a8b64b704776f190a4baeb55