Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (lein, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-lein-fips, 1-debian13-lein-fips, 1-lein-fips, 1.12-debian-lein-fips, 1.12-debian13-lein-fips, 1.12-lein-fips, 1.12.6-debian-lein-fips, 1.12.6-debian13-lein-fips, 1.12.6-lein-fips

Index digest:

sha256:821764e2392ff6a0095fc57cec2947d470be99ac39c1e5104013bf970b9cc19d

Manifest digest:

sha256:37b8cec1db2a87c22544953ca87e45ba45a77198e40488150ead4bac0ad15f0e

Size

113.18 MB

Last pushed

17 hours ago

Vulnerabilities

0
1
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-debian-lein-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-debian-lein-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:34456db05d21b9009ff409db5e2eec09f905556aa4c3decf21145f2c691bc335
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:20b6c6688f603b73c015d3b15deb0c32c0e5dd07691fff76d4219963637f022d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:ddea9d9228ff8d5d64a95e55eb80053bec6f55fa00505f5ec92160b82e2d4466
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:bf267c3476d8755d01527b28ad66264cd47a3b85f212265acda71d036361f4a1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:f67436ed65420aa41f4d1ef52654477b332d16b0cb1ec3bbad954d3f1236bee9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:30220e428e5dac3b3f615a183d853ec20b2dbe043a8bc07e1ba93bcac31370de
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:63067d583d099e06134f9b448f26927b3d02dd96aa42619821df28965264670b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:388adba0d28a4cc841a521ef5ac7d45ae95c17f068704211c054449ad532ee82
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:47d159f62f60c6b1df3ad5aca4c8240d487af9ff97c7fac7c8e6c9de04bcbaff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:de8847641d764398b39455aae5eb1682b216d0dd172e2c37dbc40f146c221d3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:8fd9af97cf94f79105290ba4e21bd5668610ab8b52da4688d00cd1311796bd10
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:8e0da868c9fc7b3e759fc6602c8eb82dee4429ec7b7c27c8075daead9825aecb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:d133af754419159a6dd8ad95dac6a5c257f0b1e0ee90281c7bb1aa78f01c3e8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:4d1074ef08739db09df147dbd9f081d399db31e2217d2c42729ce836eb2e59ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:94c1f5f3ff97257a8f9a340a8dfb7b7b4c4ee7e5731dd2b604f22933321c8846
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:1a466834da8a288e5006328bfde5f4383fce301e8175d88775c85dfba5b095c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:38e764de40ed92266839ef46205e2fa0d914dc2bdfc66bd7574ecbe81744665c