Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 25.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

9-jdk25-alpine3.23-dev, 9.8-jdk25-alpine3.23-dev, 9.8.0-r1-jdk25-alpine3.23-dev

Index digest:

sha256:b0a0e488d7593730950f6869e7fc49c83365b09d1e00bf111c72ebee3dca3207

Manifest digest:

sha256:090e63902dd2c4f09d333d1ae6700e3d91cf297ee12346d770d5a8289fdc0f0a

Size

269.43 MB

Last pushed

2 hours ago

Vulnerabilities

0
4
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk25-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk25-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:d2609bcddf8ff327d379b1f8fe042ea8c60af0fd9af5c69aaa540f51c47a9a38
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:b7d288369b84e935bdfafaa39391676684c669cfcc698c56d1a5458c177b0498
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:2d091a56a3202b6dfac40d5e1efd291da0b3ab314ed6b05a8afdf37d495d295b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:477ed7ce02dd818b947b4ff26c15fa3b4387d4be87d8d02c4cc0b2340f24654a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:be1d848e33504d667bae3ea898190b01d4f1a7e30724ae6afe27336aa87d1e9d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:e5162ed7a251634124b0a13b05a53f5aaa3f6ba1f5e82d4a6eaaf80f60ae7350
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:c5a017caba0572343a76ecee2366dfca6c2b0537d5f55e3a8a3fa20b82e30d30
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:ca5695956dad5fd1aa6b7314888a56716f95c619a12bc30dae1936f706cd0a7d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:77a056e9ea48a7ca76dc98839df532277c426b2875117a209062c31a37099edf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:2a9a2df08579550d5ecc403d6383af68aeb44bca706356d02bb1e7771b2b8321
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:dea82d580604984cbaf8590def670761ef1dd6b319ef3c8a153652e31db30c9f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:715dbb14f6fcb743f264c6a6cf5acf2b6fe2e634c5353b17afff603be30ea321
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:b3e1b4d6d980831e355f3eff9ee6a34507f165ff258bdbe8c2001f2d4c28feaf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:70d6146a0508ee604c6e922af0d531ecef586857086fda2f21dc1dade4d1bc0c