Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine-fips-dev, 1-alpine3.23-fips-dev, 1.12-alpine-fips-dev, 1.12-alpine3.23-fips-dev, 1.12.6-alpine-fips-dev, 1.12.6-alpine3.23-fips-dev

Index digest:

sha256:048be8017d7663b358270c0db52e35c3ae3df82cb43de8fc2efae5304ca37eb6

Manifest digest:

sha256:8e7e9bd7c718cb2407288b61b5cac082a0a5881f8f26608f9f8773d67a143593

Size

75.75 MB

Last pushed

3 days ago

Vulnerabilities

0
0
2
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:f933bc2362472735a7b12bbb5108e2e730db25cdeb814025ac0eb9ffb9026fb7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:e37f016fb39195e3ff52e981c287d43af58a6b34ca8f45f12a696c4db858bc04
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:9c737dd32db1a92d2333b895adad66c50a5d9e32f46fd5c5630344a02b10052f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:0fcf3b8c2a8fa599d5ac77077fd61f56d04579a961dce7dbdc3e4b7b59d0449f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:ae1f65a03ba2621c3ff3a88a3c6fa6e79333f1a494a40bd3bee3cc68dc4157ed
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:754798faa87501f0026341bddd3f65f1b554b2088fac70a7d6969439df439ae3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:9f1db9640bcff2f1b9da5e93e9fec430f0bad5b72f51c83b6f6b12f87188b254
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:424e7e2dcacca76d763aaaaceebcf1dd509e8bb6688e775ec6d9725b25455dd2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:5da622bd56c40a8677c540b743fa18c9476d97e8e99ef069d6666d1783530176
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:6d98ee140344c33fb0107398c4da9c53821c4d84d77936005b260c09d4ac75d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:b033338ddaab4dd723a47feac6dbf2b043cf6da625b085121044e63c7aa72efa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:98bf7b605eed9ec917fcb2c19facff23ea822b10e55f9b904d6731f44f07047d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:edaf73e8e3268950c4b237c3c3e7ec29fa09df63bf60109b7d01084d6a6d2c77
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:b72798d329d6e65fba355e746943018f857cb0d1267dd85d71b741100a521a1d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:8bd4fe6986ab1b265b5a438d394d6449e168f2a52812d7b98c18c4fbb044871c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:3beb1e24fa703109c8623aeedadd16c4ababf26135db5975878612e393f886d9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:77b9bcb0a04da827758a7b7056539cf03b358b497e782e26caa5c7e72f65db16