Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine-tools-deps-dev, 1-alpine3.23-tools-deps-dev, 1.12-alpine-tools-deps-dev, 1.12-alpine3.23-tools-deps-dev, 1.12.6-alpine-tools-deps-dev, 1.12.6-alpine3.23-tools-deps-dev

Index digest:

sha256:de10d9a4320d628ba004278efe30b377a638fb985fe1291c1457ceb7e937a68f

Manifest digest:

sha256:809b9f634fbac158d9f6f4dda7cb2e0041e416dde30f669414f449275a5b8967

Size

55.73 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-tools-deps-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-tools-deps-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:382811966efa6a689f78b65f5c7d6dfa996fa99595b0312026e2a05e1c95848a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:1d3a2335632a735ec239addb8bfbb0559801dedbf49ce153b5e31933265e9c0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:d5be62ae4285b8a4f5674a008eeeaa5f477becc621d9ccc561cdb9dc75d9e5b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:3fd5e1ae0993d88c47c62426e9c0caccf87868a4100d0ad7125d93ad47f4cb79
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:00fcb6772701c4859b9446df87827d0e0e35173760d3e854ab089c5575e27c6c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:c8cb1bcc96e90d46f739542891cb60ea5a4cba44ceed4c965b1f9a1b0d145227
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:af4066604ccfd6ac58387ca132ba9c318dea574b7d6240f68d781d4d7ea33e75
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:9a2e2dd5d02085025bf2eda02b78e19c13256a4d81a77120c4d1b632d2556b99
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:dfc8cb7696094e115e9736ee3a6583aff7d9852ecfa4d0d8515d3c965767daa5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:b1e28f3445e20664d89e8fca23b6dcb302d50e51128be524f28dbfe6827d151c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:88991e880dea7f1de56a074321d7f16a7f154da54989c5bd058d2e056fe7e890
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:690cdf27eaad4e702120da543094032645e61152a5f7db69e0f6cdcddd44516d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:a52cdc9d194570cac0a2d1267c13af25cb8827f0f91e506d4eb09c9a1b3778fc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:3ad8061b4a68a67514f166e7b4f43f26db80faffefcb89cd0c482fe1c171e1e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:1987bc9f80ff942f1da53e7b9bf9faf735f0e3c4fb63f4c40d9f5202a654780c