Sign inSign up
Jenkins

dhi.io/jenkins

Jenkins 2.x (weekly) (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2.582-debian-fips-dev, 2.582-debian13-fips-dev, 2.582-fips-dev

Index digest:

sha256:91373b9774b22e59aeb9dd28c3ba6c060a15708e8445662a6fd6f23d66cef64e

Manifest digest:

sha256:f87bd0a37f8761cb20f2e5ec3de95c592c6f53498ba3040b7c47cce9958a583d

Size

244.93 MB

Last pushed

17 hours ago

Vulnerabilities

1
3
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/jenkins:2.582-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/jenkins:2.582-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/jenkins@sha256:d01cf65836f7224fc5c4ff7a3e59a823e64e75ceb44d12319cdfe21309befb8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/jenkins@sha256:7c9ae0b503d0db02c0b095ec37761005055b3d1511e68107fcbfc3ae10530379
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/jenkins@sha256:250200864f614fcda223107ae9d4c33db0ab92ee6b12e5bf8312b0bb9a61835d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/jenkins@sha256:2af54e1270e63fa6351e4698828dbde2f5448599543a08c3d4f62b8ae815a3bf
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/jenkins@sha256:f1fd0c731723fe5184a4baa3b36d7f8d78e1f69ac46859a66663ce956ac89da0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/jenkins@sha256:21296d016c552b637cf3de681eeb82b2b68fd470023554d2729d69a9a9013ba1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/jenkins@sha256:c82a65080e399a208541eedb3f7b3c9195030445b2efa6e790cce25576be6266
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/jenkins@sha256:6a08d8276cf6795b2722c97ad2fbf513914442b486e7275ebc737c8b21ebcbf2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/jenkins@sha256:a852db2c32a76f8d2892001c094d7ba0a0919057073515d90ceb8f4a931fbd97
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/jenkins@sha256:bdb754a36f479d0fa7073f046e9ec5432270a8686976bfd676dc048e409dd6a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/jenkins@sha256:6b976e89a36873102eb424d2ec860449575d55011c2a39b965b2031a008a26b0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/jenkins@sha256:b13724c11cba700e4f10eee3e55397fce336f230fce7a302e5990fd2763bfd51
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/jenkins@sha256:03d061ba8f84f8d8dbada4dec56276af1ce22c635619a32bb08f8b7f8f0ab8a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/jenkins@sha256:e029db6efc7eacd35326038b3abe08c6ca6142093c8bcb564885e2e243a4bb5c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/jenkins@sha256:15800c300ddd912251a57f3c19dc9d6d2a63a8af32728bd8c5a6c7eebd8bbfdc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/jenkins@sha256:f1a1382a2cb9f3251d15fbd49302ba568c70b4d4587dc057a52767a409464d92
SPDX SBOMhttps://spdx.dev/Documentdhi.io/jenkins@sha256:a0bb7f804e8e81a50567846391ec28f1c3d58e0599c140a393e0e042d21be166