Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine, 1-alpine3.23, 1.12-alpine, 1.12-alpine3.23, 1.12.6-alpine, 1.12.6-alpine3.23

Index digest:

sha256:15e64a79411318f7bd0b6f9c5fd7074e8773ddbf09f44a3e6cc878223ecfc942

Manifest digest:

sha256:d7798633b6a01fe2ee09f2753015d8db503d93c75bfebf97ed35f57d1e612cab

Size

74.31 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:554c9556e265ed0c974b54523a755f8256991946b6cb8ca98d2ee793ceb89cc0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:6929810b02601c327550cde3cf5eebaa51928c2a570fe1aacb688fbfa01dad65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:84871c9c42a7bffd046209e997b746b9c8db5894f13b5e6341418b8da5bd556e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:e3ea551cede901e64d5dfb64d06f019718b8f48870244987300deb3e202b6681
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:2f19e377e6ec67eea042557ea670e1d3042b2cc868f6bb3dddca0b205d205a02
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:44a2fb368e938e9d5c19771b16946f466c598d2feaad66c3d62c8d027ad169f9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:050aa260c4807225243b6369a677ef04975a66861182d00eda18816fe651f141
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:46c0983a8ee04904b17fccd8e32dc88f54d2005844f7654b2257ed6c45473b68
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:9bd91daf592deef0d76798400a161b054c86908bed127f6371a0f07b792e57af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:8ca0a15ec229ba85b69ac1478076b30df0cd8a825d100e6ab3f11b91fc95b0ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:7f6df5389ef7bdbd84014465305e4f1ec0a99c1f2cc3de454f425ad6e770d301
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:7c70f868e196515309acb067805d5601506710fda735667b3511f2e8990cb25c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:2b99a4d3d0f08b54cbda11a16743c016a5e57b592d6bd36f8ff1a9590e25113f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:12f72a16c016c90ff473e799a84245ff56ecc927d4453b5f0be7506e55d644b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:cd12a53cb4541f08c36790da282042c42e46dd69a76e318b8ae33970a7423ca4