Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-tools-deps-fips, 1-alpine3.23-tools-deps-fips, 1.12-alpine-tools-deps-fips, 1.12-alpine3.23-tools-deps-fips, 1.12.6-alpine-tools-deps-fips, 1.12.6-alpine3.23-tools-deps-fips

Index digest:

sha256:ee65b0af1febdb70227378cecdac5c33e467972ef547c122e04461ee46a3a1d5

Manifest digest:

sha256:eae537a449d5f3a1cb3b07592292836543326fa501974764e25f6389e426acb5

Size

56.79 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:12df534375c5eea96b3868031ae6c0e735a96535d246106687ecf801cefd3cdd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:5e59352a66078a2e354ed758bb3074eb7217d50398ce500f681c0faeeecec6ba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:a1875cd918f946f2ffbd3a78e8e355a429188868475b4e0be4ac0262a64aa70a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:a73268d3398458ac09234a697f131fee047a319bdc5107e64240c06399a34dfb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:60b0ce345d1713dd7a00c607db529eebc2aa9d92759a920800599afb990efa79
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:2571b6ca5b00ce921fe687be56c14345471e641bc45e7d89e09fd9de4430180d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:8f0f855481118c3adcb8a479a482d909e70cfc388dfde961e7891fb47f99dc14
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:42a5a5a43941d90976aa57b0dae867bed829393003b64788965885cbb043ce29
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:8cdbd325722ff99d26fd15dcb8520087c2a02abc712484ca215bc7f6ba1e0639
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:e985400f469e40f21a0a9ba2d23a1759731fa47f52585c706f4e2910efbdb00e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:05acc6c754ba6da839cc79810a977693fa631139715947f3d191f961267d1898
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:6f6a462652996041b4ad47ca61a59935ed6cf5457ab404e4e24ab5b4b5b146e7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:e46b6f8ba6d5226bb15db1da5706879a683fe68daac78b14068d60b7432486a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:2a5d257434a76cb91eeddfd36ec9da23d1b2532dffbea2a3c57149a602048bfe
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:bb58d12fafc91a5bb4634d170a18cb3297602db712a183d265754b3e6e518d14
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:72f089ec7d8c3ff034a76d5e83dd026a06f0a81315ba0ea5deabe7fb259792d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:e6bb6034f77b9019544c80c7e1b63cea3f90f7a02e082ce0b1b4362fdf450353