Sign inSign up
Gradle

dhi.io/gradle

Gradle 8.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-jdk21-alpine-dev, 8-jdk21-alpine3.24-dev, 8.14-jdk21-alpine-dev, 8.14-jdk21-alpine3.24-dev, 8.14.5-r7-jdk21-alpine-dev, 8.14.5-r7-jdk21-alpine3.24-dev

Index digest:

sha256:59eed81f9bc6bd9915bb3f92a27b19a59fe79f76bc6b1d49e0c7238aa0bb5b85

Manifest digest:

sha256:3efcf3ab618f06bba03104687f19ce22ff4abf162f50fc38804bec757a46f4e4

Size

318.68 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:8-jdk21-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:8-jdk21-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:cb213647ac5f865c5ddbe16b080f5172a21a750dc7d3bb030af99ae3b541c004
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:f65e8e1dd00bd9b8770be0d693a2741b43caedf636d923027c0c1a46c099dfbc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:a904abeca4b09439f409f8c870576d8913b5b678410c53aada12a921e66365f0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:937277db6aef51a5813ca140068d22360dfb4ee42384288dec40cd67f1a2fe2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gradle@sha256:edacc6753d031191d882de022dd921844670dd8dff35c2dccf196014dbb56fff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:7a870309675076de6b770eab544e366f8cc700b682df720f53b755ea6b6f42fa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:38d821e93d6bf9ea70ca93bdad5fc4ffe2645c40145be0119ae68766bdc2b883
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:ef76482fc31aecb5c66a24a859fb8f1c367ba5e8caeb882b6efbfbeb203f0965
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:91690e5b00cec1f140686b54faab22dc6c0a760bc1cd26d69c6e640900e54559
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:ad14f981a7a948db04bb84cfb26a569c7b3401279b8c59c83a514a6cf6441ffc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:60104c753f30cfb8f1585aa67fe6f49d9175586b59a37f0ea3f6ced2d7f8d24d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:dd6fdd85d58c86f6a522fe125b3d2765be2ea871d8600ee840961b0b6e4a5d78
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:c1d6df4f76d252c8b43ffe0b40f6d1453c13b611b0741abba0b37b21c84cf102
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:0e17bb5eda0c650143ecb9fe1f5dca5dfad48cf13cf26fdd5bae6482a95fc265
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:7227e863da5bcb3f6eabbca3cd2c8ae670a7124000a36d6d5ae96f7710c4d62c