Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-tools-deps-fips, 1-debian13-tools-deps-fips, 1-tools-deps-fips, 1.12-debian-tools-deps-fips, 1.12-debian13-tools-deps-fips, 1.12-tools-deps-fips, 1.12.6-debian-tools-deps-fips, 1.12.6-debian13-tools-deps-fips, 1.12.6-tools-deps-fips

Index digest:

sha256:4a4481f304d1eb7b0629ce5af846fd35f80ef24000f5af1dc085b888ddf3445e

Manifest digest:

sha256:35811138a79f9b43bc94613ac02d8068358bcf5e3f7721975095a4e2c777eef5

Size

96.25 MB

Last pushed

17 hours ago

Vulnerabilities

1
3
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-debian-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-debian-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:e767ba299b0474f396dbbbea2ec936058e4a055a7953fa9fa597d25260c4bccc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:b790e6a58faeba09bc10545f3457f705b4cc66ef414f891ee1a3879cf4040031
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:8dd88dfa9cae5611d5f8a9c8b9d952dc3c1b5bbe2f342fa92fdfaf24f3091c71
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:22ad39777620c70205b00fd4477a379b2863d49138c4c2c79ead1114c68d3b1a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:896d7461f9cf8e3f2dd052ef7f49902ee8c409edf757af5a0acf8189c2b5e912
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:52d2a5ad11680e9b0f15c96f87917a7652615d6cb465cc3bf4d1515ebde72835
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:2d81ec7dac4347ef86b5519526352e4612a08ded3869f1f5245b5360ed9ae20a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:aaad57a784f69781ae3e0bfb5ec1b8ab8d42d15fe46131f9755f9243849a7927
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:e44ca60c465fe8153255ec795bbe02f6a4dc821366328fe4f748a284488a4d82
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:953358dddb30e353c4c66b7f78c45d1ca58250dbdde00438c70b7feec5c3559b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:d2d5a4c8ec811f400ee2a2b7812751ae99cfc95e8494d219bdff3159f4981c60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:ff4752b79c342fd8db3b5b388612d1797d356d2edd20354942df6be1f2a9204e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:ff11fc18f188a21f411f76266ea765b8dc1648f2e315c4d0eae922d96a5b49cb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:f1dda6aefa2bd718fcd1579ad2eec9d055729ba9028000da5a61ee63e10bcd93
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:574a3cea30b654d83f719bc435e00b3341ee19027d900340d03fa9788d1658fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:d665187ecc05dfc4b578f6788c4c9a72bca1982f60a21b7ff2c0eb1868f95a04
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:9ba7ff83b0c463ea81d9d11c0f7849027a02970e711c4de14cb03b74e76d3f7f