Sign inSign up
Jenkins

dhi.io/jenkins

Jenkins 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.568, 2.568-debian, 2.568-debian13, 2.568.3, 2.568.3-debian, 2.568.3-debian13

Index digest:

sha256:183db571be30aeff8a236776a9b96a744c369566fb0e96fcbace89b5b164b57c

Manifest digest:

sha256:fb0c18eeffce9b9df6b90b1d7d07789f8d3313f4968745a67e774b6b84729eb7

Size

179.66 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
1
13
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jenkins:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jenkins:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jenkins@sha256:48c44f848e327d6fdaa14a2cc785901a58a2c7bfd0e8379a2ea1d1d3d68beb2c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jenkins@sha256:322048847ea66752a5bfc7eb7a151c0aea93ec50defe4c4994c421d116076a81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jenkins@sha256:3f3817f0647fb66fd2f1745783f476db3214bc3f7b3c2e67f851dc42c5ee132a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jenkins@sha256:ffc555a832f005208f7639f06ef8b1a0dc7e50dce5a2dfa7faffae44fa5dfea0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jenkins@sha256:2dab8ffee55ebb204585df5e960d2712c32c9b4c696c18fb8f1019514176f1bd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jenkins@sha256:8bebdecba1867b6ca5111a115c3c2a0209db113be52cccac67410f1deb7b9c40
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jenkins@sha256:c2ba182287730b7aff2f6d0be792dafeb19781f3346780c2bee4c5cf3e354d50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jenkins@sha256:b8af0b92ad6fc7bb77e5438b51422e13ebeb6ddb089f559fc0fe51e1ae71e744
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jenkins@sha256:4a769e7e9cca7a71149e13a8f69e2a20b9ce8fcf0e98abe6b2e4e50c463148ea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jenkins@sha256:77740f5be649debf5794f9dc47e6d111a5e1751ee412b46320cca5faf4d51d3d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jenkins@sha256:77e393f0ce19d1738137610ce85aafdd45132bbabcb9f52ad06e313b23680121
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jenkins@sha256:25ea62c0e944403a2f6cde01bc1c439e8293525b9d80f3fadca992ac98b2a52f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jenkins@sha256:37ffefa81691f3c99c64eb19462040423844e4c9a573e296f2a68e54e1a6426d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jenkins@sha256:f25575c8d06aa76952c067b551a79d0a745f00f26aba1455475025698f493ef6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jenkins@sha256:69dc13b71cb08aecf1ef94928bf21df7138d6130d324798f4cc149c2e98fffd0