Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-tools-deps-fips, 1-debian13-tools-deps-fips, 1-tools-deps-fips, 1.12-debian-tools-deps-fips, 1.12-debian13-tools-deps-fips, 1.12-tools-deps-fips, 1.12.6-debian-tools-deps-fips, 1.12.6-debian13-tools-deps-fips, 1.12.6-tools-deps-fips

Index digest:

sha256:4fcabb48d2191649e80a3b83bd6f26d0ff45469f4da7e05bae37e2b061f4c46c

Manifest digest:

sha256:2b612d1dea40636014a1edc64cdef1ef66cf5302e2b3f2e88dde5264fb3941d6

Size

96.25 MB

Last pushed

22 hours ago

Vulnerabilities

1
3
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-debian-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-debian-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:3e923110d395233fca3b91d3770d02a823c8477ae9c7a142c3d9cd3c28606b49
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:c1020e415e614da153a285594a6a7d2bacf0a9ff5dc1fbe9556312e5ba1eb2a7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:d2cc8c5c9c1f8af4c7f2ccd31e533988febad422ee72b2388b6bfc618b4e19c6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:4cbde701513966aad4f8cae9f5c0df9557a7b5c14a2589a388bc48c1bd1e7a95
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:6465a84c3fa77f5d3b61ddbd2da488df49d6a94beb257c23ff44c486c13fcc0f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:2280407489ef9c1557cd38631fce7a0b4aa064e20bda3178e8e7c101d945b414
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:74544cba555fefaea7c6edd42a22bf96316dcb818c0f0a796345d1a1b52991d3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:eb09357a98cb89875b8327dc778de6f21a9614678647269dfbe96642b6f4fc37
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:e835ab919e507f8a8e3664d6dfa4600475c872698e09164d1cbed4719cde4dbb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:9a4c9aa3a458451f379e8b11241fbb3f05247581d40d8460fd89f4dc0d2105ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:57c828788fd8d53107e791bb20beb6803b43574d981687c6e7374d31622f9cd1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:3ff1ab18478e2b4d37e8a0c66bd91fb98ec75120d6734f0633e725bb0565befa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:cbac81cb157581d9e74cdfd4016a0e830835a819b55d8a1c62fe4c0ccfb374b3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:8386103a3fc911b54da968d4cd58c2877af57a7bc16af3bc659f7d39a01225d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:9a6845db2d975539f94257b4ea614276dcfb8e23ccc9cd9a5c5a7846b5937126
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:2168d0be1f6cc8f8415dea9eaae5b3a03291a0e93a805fda2554bb3083228b94
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:3321d35a05786ac414d3443f4a7f2d35a75e05ef0272b3b263c056070d2f5fc4