Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine, 1-alpine3.23, 1.12-alpine, 1.12-alpine3.23, 1.12.6-alpine, 1.12.6-alpine3.23

Index digest:

sha256:cec3523dbc0442fb423dd8f7778c374bece9a4c38c6b4f3a1ae27cc68345b1c0

Manifest digest:

sha256:10d5b1e9884ec3f3007be13f4dc33ff845f206b78f7898f73f9cedbcfdc81613

Size

74.32 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:d846a73cd3fec1a821a508ba7a91e2fae580fe4d331e71f9d5a6db75b3e0b7d4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:4c0f84f11d699ca217af84e90802bcd80d79de9a47b994a1dbacf5397fcadbca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:9dc333b37c4ad61369dbb7cc4fc2f9bf7150d5f1f204cef17ca4009facd5f196
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:1804b126aab41eb66b03855419f29392d965604ef74cf863c9cdf9fc535a7324
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:f8cc01abb92f8f39e6d9f5de6cefab73017ac8b404bfc8b0754d6d94c0d7cf6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:e4000796830a7b371fde7f769097b5a47beb363abbd06e43bc9b16e3f8b47e42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:243fb21e85860494253eab65b5492e170ee632bf1fe2dffbce61535f959350b3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:092ad1e8da30526f0b4051770b65c882e21de7de4b103cff462bfd574c9f8b78
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:51ef4e3d155429db0a3282e9e06f801a820ffc836b56aa52f5d19f47126ddc0e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:17ae9d2f26644f229ba84386e1526c5587de449985e2b9a09a71d8763e847944
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:cd3a972edb620cf2b05fbc111e6587e6800c7d87a3ee8408dd09786e04412a1b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:319bac45f4c25165e42317f1270e6eea9aa4283376658898abdcb6512193be70
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:e3d57df877159d270453dfdb893dfdd69394b9db332c2cfa3a4602e0bd374f18
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:cef5f82bdfde332f9e6cfab6db871e7b4c304c078afc04447752330c7f7a1b60
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:76994c5fd612a2db3daa1552db37e9a66df3764431d412f3472920b63850aa0d