Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 25.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9-jdk25-alpine-dev, 9-jdk25-alpine3.24-dev, 9.8-jdk25-alpine-dev, 9.8-jdk25-alpine3.24-dev, 9.8.0-r1-jdk25-alpine-dev, 9.8.0-r1-jdk25-alpine3.24-dev

Index digest:

sha256:862a70baa7af0f936c136d4629d1a6edec1c86c0f394abd4a7de50c9b7a33c20

Manifest digest:

sha256:ffe87ae6c6b222c85a1d3f645f07954e34e99081b65fa29193fa1a1b207e766a

Size

269.43 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk25-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk25-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:01309d9a37354c44bb3289c011d8012bde496d90505687bb0a50863f6453e841
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:e6cbbdc9c6fe94e41b149a6700b7c0a08a1609c1d03f452539c2bbda0d169207
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:6be7a1147f43a7756aedfc95c103eaee795d92cf57ae3e465dbd1871b31c77e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:d41731617d5c8f0f60eed78b7847d3a8c3934dea3a1aa9bdc55bd3576d2b21e1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:af9e3fcf3c53b76bea9e4adc74a6f17db7052b88081973340d91047019580ae4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:8d413e59ff8d2dc5e2e71e9498060d21437564ddd577095abadfd0cb895d54ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:9c5fa7711b596a46edc7bfd13bf021cdaa3d2f984f3ec6d5ae4e44eab2d39cec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:4380e49a92a4ea5becd40a0307dcd297fe3910631f265a79a9ffd5136a95a10c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:dc40705de667ad01a6ddef5c2f861e7a0e1571aaa338c9f9aa79d53038781c16
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:5f6c9573ba3c7f5191d97d6af35ecb1ff778705159c72a126b088bc2589e7188
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:cdf0797242dbf1907bcbd9fc9133b80215159778a96b6b6cebca07aa09f1c137
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:cefc7696bc49dc9853c0c4b1235fe76becc450f7a31c7c8d0ffd926d53819973
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:4c45bbeea01eeb72684d3b2a8f75e020a59bb6f797e2ba0e1ef37059330f936e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:8fb17c2e3a0dc5ae9e65e00d650044c454f3f91531447901d384d4c0a5401d78