Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-tools-deps-fips, 1-debian13-tools-deps-fips, 1-tools-deps-fips, 1.12-debian-tools-deps-fips, 1.12-debian13-tools-deps-fips, 1.12-tools-deps-fips, 1.12.6-debian-tools-deps-fips, 1.12.6-debian13-tools-deps-fips, 1.12.6-tools-deps-fips

Index digest:

sha256:82b47d470d4ca2e434096b759af346677040c8055e2f3a4741901b0acb2d4338

Manifest digest:

sha256:14e216730946bc0eb4045c7898d29889d7cd21ec9a2bdec4dc2399fe2e3599c7

Size

95.56 MB

Last pushed

13 hours ago

Vulnerabilities

0
1
3
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-debian-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-debian-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:98c2b990a510b3166884b95ba7f75a025e417f5942efa9050d2c1e421fa9a85b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:7811c3d0e4b1041121118de447f7398227b4a39fe0961bee31c8f2aba2487783
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:b2463f671d7d7689f61ac714918a5dee6bb2578d5b1d3c02d1728c4ea8c6e50b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:71aad2654b60ac61c78e8e43e2f5f5acbd8a7f82e6a4e66aff05088b3df13aed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:37b6fa2ed7d135764705e130f48d3cc2dc0d5b74dc8ad4523bb1059ae95351a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:940acb7c64febb9a7846f0ffb279bdc5ef5de9d6d827f75419005f94b122dfc6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:4044026ad350540a085e51c9dabaa26a98cce9991e9db9c7e7123cce0dc84d79
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:6ad385e3f179dbcbc3873a7279114e42aa6d6e92268a4d529892bf36b4040245
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:67f04760f1689236d718c508f46b3009d27c09966a9e8c84f90e988e5b00b3c0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:4b822a8486058e0c730633bcaeb16210b8ba40961106bd170015378bd6a09aa6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:a7f6ac925edb39cc785424cd2c66696b95e97f67f223916cc1b67fd8b8374d8f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:be7a82cafe673e6eb90478856cc3ce3001f3a9e377a5717e8d579aad5e0c9940
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:1191b086627bb99769e839584d27299b4e0b8adf10d48ca49437d288976a3f61
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:69082e98770692c1e2d710b32e3d9764f6a134b8331772a8531a087820e62e7d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:2cb2e4b4aea5e7344c172992698c8547d26a7104450bf6cccb8910d9a0330ea5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:9751d32165ca4534b357f11e363953053144432ed098fd0d5021370d8005c219
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:bdad60ca564d25d64a62c576dbfcee9ff8ce1a673a3bd221c04eb1e0758d302f