Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-tools-deps-fips, 1-alpine3.23-tools-deps-fips, 1.12-alpine-tools-deps-fips, 1.12-alpine3.23-tools-deps-fips, 1.12.6-alpine-tools-deps-fips, 1.12.6-alpine3.23-tools-deps-fips

Index digest:

sha256:781ee9cfb135d84335ec4c7cd4845f029b8f6e34e5161c8ea6d96e8c7a389ca7

Manifest digest:

sha256:df398c563c1be7bfe3efee32737f0a6542095487983b9e7e5d564b1d2b1d7b77

Size

56.79 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:ced3645dee8e46007c1557474d54990ac14bb9bdf75a4e59a6455cf4c9c48110
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:f903ad05788a4fbd921c61932975b13c38581609e40138f083cdfd164ba42195
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:5ea8e933b50c7451b988b3953dc59d1e46c7a35a2c2960b19e9fdd3742ba9161
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:f5b0f2dff3e1674ee7d1e8e1c7d39bfb743862a678633e34ac6225cfb2d14817
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:276ba457e164c2ebd785eb552801b9b796bfd0a1ca5c0f5b2a728d42fe5b6637
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:bfe3d0b5ee2948a026f7ac7bc9e47704da512cd7f06363dbb368d9b9a55f5de7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:060968eb9a2a8c0137055b9c7a7225882a90a0405bbc4e650393391c91fb37e5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:b809d9a21c8cb779a1e248e5a82c4bade378dd71ff7df57df315d851861c52f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:b00f77e9692bc3bc1078c7a8111c26655ad8e008e280761117a916850cf8ae50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:c44de0388e15ba221a39b6d79d144170bc9a25403a680f34dc6c1f9bec82b4a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:e7826b8e2fa66986633da0433c4b7defd1f63f5d6445d5d55db41cef0bced6da
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:e3cbf786749d6fc659dbe5b902e2345fd67850108c0140fad65fee21ea988f79
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:3382457227b8173eab0f828d5bbffd7fb0019174bed715df02870936bb666c4d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:3e44a5ad014d2399b9984e458e3ab6a58df9744a20c105a1872dd3c3ec179672
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:76f3081b2e1789dd889d4fa16a7d119e7aaeb72bd1f515fa478c2b3c137b6682
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:f190c983bb9bb7e1ebea1c048c1ea5667542f0644056683cdc45419bd6232e62
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:9b11fe5c10ee24da1c4da9f6974383a3c2ccc486ebe0c9308606adae1086f8c1