Sign inSign up
Maven

dhi.io/maven

Maven 3.x JDK 25.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

3-jdk25-alpine-fips-dev, 3-jdk25-alpine3.24-fips-dev, 3.10-jdk25-alpine-fips-dev, 3.10-jdk25-alpine3.24-fips-dev, 3.10.0-r0-jdk25-alpine-fips-dev, 3.10.0-r0-jdk25-alpine3.24-fips-dev

Index digest:

sha256:2b6a2687c9bdccfd0affcdf274a1726a02bca9583d3f3ae27c4730405f1e988a

Manifest digest:

sha256:5c8e9101c83df377b05ecdd8195ad750cd8cb1ac7347251c9a97a9f44caaac7d

Size

141.44 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/maven:3-jdk25-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/maven:3-jdk25-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/maven@sha256:9c784492980bffe48ff775c723c76c6808192fec3a9700f1aa57bbf428ed729d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/maven@sha256:01de10d5174734503fc0e9d9730b27475f04d52b5d12edaac40fb665325317cc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/maven@sha256:d66cb40a4b388b6767ec009fd5cc16b331c6b0fc4a46ea421e1d43316b6992e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/maven@sha256:a1ce95c85e3c17a70af4be63613f1caaeae0a8c118c506c672d449c5715fe978
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/maven@sha256:343dde75814f9044af644d0d3f054a8cb1b7e87f3965d64d8e3afccae7a96993
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/maven@sha256:cda4b763788cccd4c2088d809854174f3d42e69f2a91a1010b44cfb5e626fea3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/maven@sha256:b9d6a746218bde8eec28821bac7e0530bad169fee1f7d58488321e354dcace29
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/maven@sha256:9d18bb0cdd5b013bcd6de00c33bc51683ffc8ca6923915ec25f494a4c39793c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/maven@sha256:5709ded58fb9ed0fe3a9f9f16a4704915e12d1995239ee8ba5edde3bea30f475
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/maven@sha256:528ce667997e831804b16e15502fa4da7c29e99f241ea7076d165dd285416f95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/maven@sha256:fcdc758d2ea646b28c1efcc7e6eb251cc72f4e098256e53fa8283a1b6dec04eb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/maven@sha256:272c36208eb7d76e05a30d5452eeea7cf1c1de3a875e60f47ce41ed72539f960
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/maven@sha256:a80072714fc42b4220f231fd1862d8fb2bbbec2649fe8cee142ee603816441fa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/maven@sha256:a7a333ef14cb2a85334f58153d85b9295869936d6373a1dabb3e8ca0d77020bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/maven@sha256:715beebeb2553b776d34aa8f60f5e39f2262f5eded98c8094748e7d13671112f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/maven@sha256:7bdc7ea6504f78ce721df4d22c781e7833d6a71b241477ea560c20a8616fe6b5