Sign inSign up
Jenkins

dhi.io/jenkins

Jenkins 2.x (weekly)

CIS
linux/amd64
debian 13
Tags:

2.585, 2.585-debian, 2.585-debian13

Index digest:

sha256:ad4b45701a3c691bf099453d936f78808ae848e9b0c4e03ee960d842c372e99c

Manifest digest:

sha256:90cf24b907d7de3afebb9fd387a25d76751a0f7b0eb886e51cbf2fd0359ef259

Size

132.36 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
2
18
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jenkins:2.585

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jenkins:2.585 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jenkins@sha256:1d3de88c5f138ae6dde2472080ad12f7acad640f35847a970cacd1fc91509e26
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jenkins@sha256:f76dbf6a771ed71d5f4eb0c8be11cf77575276647514cb066aca0a1eb17aae81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jenkins@sha256:4ff7ce7c3eabb3e2d6484a746dc5ea5dbb852c9ad871cac6d97bc452deb989f6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jenkins@sha256:0e804ca69f0291d4170cbec514655a00d922487cf8e75d6c7967af6071aea11f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jenkins@sha256:1cd6ae90f9806b5dddb89453a5b2a77287749688b1c676250212a2137215b4ad
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jenkins@sha256:94ea5bf1215158a4737c3f908cd30108f25d88a9e9e2b64e4b5fbe77667b48af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jenkins@sha256:6770e93979315051a8e80653167d225293a4bc7c720daee8683ad39c96022754
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jenkins@sha256:51b6b4a292093dfc1e2f64eebd6e9d62a67076b13a4a9963a99f959ad8b8cc64
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jenkins@sha256:90cefe1ac83c8ad878b74fb1481295c21454ff8dd3ab8a2010a77e5d4482ba18
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jenkins@sha256:16e3a5b377c4f8b256ba1bca3a99fc9774f204553cafde62a74e9517b8f3d872
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jenkins@sha256:286e97bb631561121837a2fb004cc039472b11041791b51007afff94e5beb78f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jenkins@sha256:5e5f873692bc8d3e5601b756a0f4552021ea785ad83e95c904683414a200f507
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jenkins@sha256:2c71047406712ce0f4cc3ea2668e4adbc1cb4c1b7c0e2cc38419012e3a3f43f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jenkins@sha256:426d56823c6e36326b2690d08cd59f78e78767b31591bf58282838c57d92145e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jenkins@sha256:3330f075329f1759c082fb0fbf0cca291de9455a6c1a62750d92f4d0a7ca1e22