Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-tools-deps, 1-alpine3.23-tools-deps, 1.12-alpine-tools-deps, 1.12-alpine3.23-tools-deps, 1.12.6-alpine-tools-deps, 1.12.6-alpine3.23-tools-deps

Index digest:

sha256:1b24724d9ef82b6d8829015e7f6d49325063047d8cd3bcd8cbc04f0b61ca1210

Manifest digest:

sha256:95de43bb1c9f8ea359d5349ad20f54e3fecd6fbd30dcaad8b0237c81c02a78e5

Size

55.06 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-tools-deps

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-tools-deps --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:2e7b864a81833da72e47943f963c9a006e183ea504679e4387f7fb34ecaef1db
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:3bcba79a1b3bd94255d8befc8ee62d3b5dc13cd9b47ec088a230e600b260cc26
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:b23e3652961a713e8ad41d9cd8bb5b1249923500e73cd92745307f4245c4b43d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:6d92bc72f449540f87de368fcedabf4850f5c384bc607c047ea256ca1ec9a5ae
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:37d71f2473ba3e4084f46f651e1634fdcdeec74661c66628090c06e03ffbcfb6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:c562ab85d4f9815a8f3ee1cbcabac784b64220a787106f15d6008f4f94e838dd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:3ea6769f4d08ed0b5fbc17e175bf78b205406b20b5cb917e68cbd268c693bde8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:879ad16b16f2a84823ff484de7bde69dce2b888026a1201e3dbeaf1cef4d129f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:e4a61433e66ed1016d8b093f7d94857b5d44b69e6cd34e5e307a216f8a6cc72a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:13dc6817d98ba9a31bdf504d72c5ca3b3b890f2db9e9174aedf69b49b4afb218
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:0ebf3c73135b4d42dcf7a8c3029a4d1ddda1fbd8dbf9086113d5aa6db04b6290
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:b4e28636913a67d5d1bb5307777623f8b305b65702431a1445bf661dfe1ab80f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:bf20868845cc373e33e78214305318f8c1fe05e0c758bd833645ee5836686471
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:f387642077934483c6c44e94f6fd0376d82491d32d9de83fce43d4cc8cb34c8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:d9a84982912d2c08561ab838efb3c2504eb5777f3cd42ba772b327d30847d38d