Sign inSign up
Gradle

dhi.io/gradle

Gradle 8.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-jdk21-alpine3.23-dev, 8.14-jdk21-alpine3.23-dev, 8.14.5-r9-jdk21-alpine3.23-dev

Index digest:

sha256:89d7ce3ba562fe914ff72d1c9e8d0037a65ad68de82208c4ff4d51aa848607ab

Manifest digest:

sha256:d36cb7a445798dbec21a591e052495157b3a2eac1a70e9ac791fe1cd8e767060

Size

319.76 MB

Last pushed

2 days ago

Vulnerabilities

0
6
3
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:8-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:8-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:060c64317707143ceef8b21974bc7efe5109163d22be74174f62dd4b0dfb3baf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:83abc1b6aa76e86663934e33e6d941ff606eb48356af9ca2fa4d6c531d50d3ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:5f9e13ddef8f801f1008d28e05788d20442a4e69503b3b6ce555cf65a7c23f1a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:f601d53643b537e8079b31641c73c3d749e30efee0ac7795184b9319b3976f79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gradle@sha256:096f7df4c5c18b24e479c71f717a8eddd7716f02c18cf7898ba6c453db1ffdf0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:2fcffb56bcabf533543058ed1298fbd59603c2401ad3c859e9a01036b895a2b7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:31a88cd1227d167d6d5c21f2bd7e20bd3577121ee20eb3cf8c7e15584a52999a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:5fd0f40dfebdbc9d222b9a9f495f2118aea8b52326c24e5001ccfdb5676e0de7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:944b5b0f986c9e688666abcc217fef8031f2654571578130b99f2f10bfc8fa0e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:97605d95a0cd1649e5d1e25c750e6b599baf77dcc5bd216f00bb24ef5597463d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:eaad86486fb976ecbe94e536d8cca6300c15170a0f9f24d4eef678a4277d1d0b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:651b86e88fa236e8fe3e99cfc3cd6f9a2bfb011c2c4a6a5b42341380c419557e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:8c4a9aa6d58cb57d6d2a23e88d332a854abf89e28555cbdd946bf78aa26fc199
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:cb25be55a24c6ab5e00b5ef222349294ee37fa298da8710fc71445bb72351766
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:74a3303c836e8d3e8eb375556c4148e1fdf65210574991f9680971298c05d8c8