Sign inSign up
Jenkins

dhi.io/jenkins

Jenkins 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.568-debian-fips-dev, 2.568-debian13-fips-dev, 2.568-fips-dev, 2.568.3-debian-fips-dev, 2.568.3-debian13-fips-dev, 2.568.3-fips-dev

Index digest:

sha256:3108cd0a462da6e7490ed48726bfad2ed77965b40d444f9b9e09499cc05672cd

Manifest digest:

sha256:c9253972d0bd979702180c42dacfd61d19a7c93b505055f7eab62955efa112a2

Size

290.45 MB

Last pushed

19 hours ago

Vulnerabilities

2
4
1
15
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jenkins:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jenkins:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jenkins@sha256:49f8cc5bbe8c30f1a7784f997b7d4fd12310ccc0b91cbb1f2ab9bc4d39cd0d33
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jenkins@sha256:134cb5238e07f7c195181564dc3ed14bcdd8e19b9d1775548b4536daffc9beab
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jenkins@sha256:bcc5a0f1343f708818547e57182bc754c6b3b394f61f5b52321aa5db658196cc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jenkins@sha256:fc495c68dbace45e1d168e4075d2a27f8d84a23851509fd1f3203ac73962c2af
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jenkins@sha256:aa71f72ec7e2c5a39f59bd6c6446cbd562012a565450489a7f5024b1a265def5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jenkins@sha256:f33a1c69e145f255aa88904ea33d2181ddb0ce47ab75475dc26be722213de710
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jenkins@sha256:93de9fc80d296c1400d2333ee7d9187599281296926fe6375ae20c8960574501
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jenkins@sha256:d7fb9e7b9b21487358063a5aa04587198b3165d3e60bfbc9cc5992b08945b9dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jenkins@sha256:3f2cbe30f9962ca2efe1290a181f236e54b60cc6c3f74a645e77976da96d5d13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jenkins@sha256:9b91c72db470ed558e4251f66c5f88e84d2b5e4329595938a011c38c09db174c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jenkins@sha256:4dcb3bc186c76d40fa8191182eee6ec8eb258753c73b8b4e6f6334cd19fd5104
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jenkins@sha256:2029609d3d8839909d6fdda4f38699d4a6b49db934750f0451bc6873aefb0f2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jenkins@sha256:7b1071e1c403a8fe956ae2aff04db5a816cb22956db355c3022f8a1240c9ae9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jenkins@sha256:9b2cef085a2b0c6925d7f0fbc246b8145e1973d6f00f47933d5f5999ec19c55a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jenkins@sha256:bebf6e37136336527ec248ee06e9f6cae7fbf5857d941b6803451bbb9b14dd88
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jenkins@sha256:c622c7015b6000a83e1b56415cc84888122a6c3be20c4b59b5b316a50d6194d5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jenkins@sha256:065b3430340c57a03e448540a22f4be92d7ac89c4b4c9d016a821dd840cb619c