Sign inSign up
Jenkins

dhi.io/jenkins

Jenkins 2.x (weekly) (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.585-debian-fips-dev, 2.585-debian13-fips-dev, 2.585-fips-dev

Index digest:

sha256:bac8cbbf24538d51d425bf77bf04ae8380e2262d99b083088a384e4ab29c81bf

Manifest digest:

sha256:54f0fd022c3e32fed46d3472f19a9303a9a02a042d4db6e50e6cb0471a4f6318

Size

243.17 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jenkins:2.585-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jenkins:2.585-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jenkins@sha256:8b35eb6c0c357c791cdb634fe0740af0bb0cf2f473abe1ab324259d364745947
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jenkins@sha256:dcd745d187ddf0ea9d7df77f55a8ae93735b6a81bfb120754a258e2efa56013d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jenkins@sha256:c7e3002b16be175f9ae423f80bf6c220700b1115470ecefc15062338cd17fde4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jenkins@sha256:eecbd55bf0e351000da54ab49d6e47c877e6e3d3cfa1d33fe6e4b779ff768619
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jenkins@sha256:93b11c323f735224c70c1a7cb145ec7d5e6deba08c869232aabce0a6fa005733
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jenkins@sha256:866f27b2e0baef550dc5ec38096305a6abe3d3c746be971ad720dcd31e143a0c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jenkins@sha256:6afee4cc379015567d78be77101ffb911d8ce63de45927a090ee77e9f342286f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jenkins@sha256:1c759a08d851d6e5b86a69e9f83c1c46e051b62f756604865c2675ba4c7a61bf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jenkins@sha256:a3feba5d1b36ac55a19be5741f41a53e98f9744412d3e8c8b388dd51ac15b8db
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jenkins@sha256:0c47d37209855cfed62c4ccfceb21c74544e1e822bbb65433fc202ba74e95d5f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jenkins@sha256:a32bc8e0cb648f774f77abf7f7dda092ded8dad8b0afedbde0fb74a03ef587cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jenkins@sha256:3444e0c055f13a0646c1fa956d4be432b4e0b2c58f4eee8feefe208d743a4620
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jenkins@sha256:336b0ccf0c7135023e84057af2d157dffac588409c9bccb77e37e94646bdcf5a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jenkins@sha256:d0622b81e9b2dea3d79d29ba16b3abe1791758bbae067a7507b3fe404801cf12
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jenkins@sha256:c4b3aa0e9de46e3e0826c8d7197e19765e2a119fbc0b2f1b19110b7de7aa34e7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jenkins@sha256:71192db557cbd45d779914b1caa0b1813ab27a59ad5791e4cf72abc2406ab34a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jenkins@sha256:7c132f8b0cbe8361af849237c1a3b1a85eecf87521e3f79006736804a0fc9d25