Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 25.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9-jdk25-alpine-dev, 9-jdk25-alpine3.24-dev, 9.8-jdk25-alpine-dev, 9.8-jdk25-alpine3.24-dev, 9.8.0-r1-jdk25-alpine-dev, 9.8.0-r1-jdk25-alpine3.24-dev

Index digest:

sha256:3c58ade168eb443f10ad639ae9b3409de8905c3067e03f1a83357f4719445437

Manifest digest:

sha256:f33cebd4f4962817d9f111bce519d80dccedde17baf261074dbd8e072e7f64e4

Size

269.43 MB

Last pushed

18 hours ago

Vulnerabilities

0
6
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk25-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk25-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:669d8c3db2f6d277ec8b651e9d36141c8ace2f76d1c7cc28f28fdb5c2caf7f56
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:147382222314047f2ce6bc5873a9c66909009a6783c1a6e8fd863dc18ba17a5c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:f731e16b7cd37659181bd514308e173a95015f445d21a899103437bd6751c09c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:8cf6194dd269bb10964eb4f312b3bf6873ebb84665c1eff2abf7f415070e495f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:4297c966a8e9472d9ac44b95938a0819e9347bc346b24e14933a9c1a5da42599
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:ddf0b8ab1a9092f3c2d72978accdc0f65de668d379bb1689cf4234845d6a788b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:2b2bfe2f1c92938babdc86cd874f72f4a401c6c7cd40a8dae193c219979fc328
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:7831ee009ec5faf91741e72287aab348113c2c08edce06300bf3cf018b207feb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:5f777089837298de1ea97493f49cde85610faaa3ff18c35a911beb6a630374bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:3f94326df9305233362b564180dc9b59aecd62cb7d4ffdab3afe212975b5c6f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:97f3f9add885556de828c1d8a46e73eb6258a9cd895918492e929327a36112f9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:b193d17e6003bad17d89157a1909b335dc8f3861053700780a842eec8babf215
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:dd174d1fe27e775b045b772da46d754c28d370c46582400765b5d1086a9282b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:1dcf987be7ccb2075e31740a24b7971976c54de5a776d19fba7a059ddbca9486