Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine, 1-alpine3.23, 1.12-alpine, 1.12-alpine3.23, 1.12.6-alpine, 1.12.6-alpine3.23

Index digest:

sha256:4dbc31e358e16bc1e324d0ed3e5366401fcb613e35005b3065519017bf79e282

Manifest digest:

sha256:c79edbcda4c816d8fc4e849dc21a9077008d020af8707b258713b0b38a8f7bdf

Size

74.31 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:64d26752b6183543b296e253383e2c6696be00394068abd122c36b9e570d0a21
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:83164707a445c474c8809217ac0715703d187292eb46984dad3c9fcb1b1db5b3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:134b1e1f45276284c714e810b99ff68ee370b64b32b0914c95793ff69682c48e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:af340103568ada50f4aa78b5cc53620e6127cb5771a89257362bfbec66564f63
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:2ece70de0bdcce91eb87e191c7cb044ced77b01deaaea74c1a0c14263c188ef0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:f7e1ec32b647b39784911216d771485cf9c65e2c6220758f32e467b03eba6d3d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:e5a8fa5858875114b0ed279b56f57db205c23deacf3f2c46fb5338c77a859b12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:de760288c93f32c48b8e86862e7719a7361e737d3a09850e9f3740cda737b9d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:878a0e407f98f029faafe5d1ac3f0462e53820250b078628382347ecd11bf858
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:5831433b95548063a2eb5d5c4b9dfbcd46298298fde974914ecaca5d4e60a95d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:f052be1d5e486d12544a8fc3ea0076ca369ba721404d1981dc6d0b3596126d13
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:c1ed0a14f50b8a0f7e3f024b2363d2a1cf9cc603063e6083b9c807d4c1d6753a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:0a7f1adbdf07b9363a4dc4f5758da7cbe8ec63cd62794a1088944b81b5cfa09f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:7f11402a3cf16313f521f0655519235469b30e0b320d2237055c61c117b62bd7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:88fe524e8f347f0e2400f85a0a6ee087c6ddd17c29b844e875c87f0610fb77fe