Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-tools-deps-fips, 1-debian13-tools-deps-fips, 1-tools-deps-fips, 1.12-debian-tools-deps-fips, 1.12-debian13-tools-deps-fips, 1.12-tools-deps-fips, 1.12.6-debian-tools-deps-fips, 1.12.6-debian13-tools-deps-fips, 1.12.6-tools-deps-fips

Index digest:

sha256:62176a498f8701df9d40063bb1f00aff051382d4828533bf6b551374d64b6943

Manifest digest:

sha256:863ec432c2b2006444e6b1afbd428ac995b3cb0899849b152e7c5ef72652cd0c

Size

95.63 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-debian-tools-deps-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-debian-tools-deps-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:5487875ba3fb9a3aa17b57157ba8d83edd1434125db89a4513f2174ae42420f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:1b8415b62064115c591188f16fb7e4ac896cc3b5090a7a688c008660a03ab651
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:61563ab15764b0eeba161e1e8796fc4478ae486dcb252da22144cf1bd5a9c618
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:ae66614de1b4d184124dab9e82dba49e7bdeb5d368b8dca7230168888868b104
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:2428068bbdffa7a37a047f6b76b4fc9520644f4170fb47c2c872ba460f262a60
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:f98acce079a1e479fac11a65ecbbc740622ff22e5da0e980e8c7a891b021962b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:d83aeb81b441b00876170b329a30ee7f91a565f4c882e3a23fc927bb429cdbbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:206b891f33d01ef47c4bd2de3b03dc0cd7d3a4334414b2da2d2a15e6f8dcad9c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:60dd4843b8630c7d75a22750748ea28ee788fcf3931e8ef01bf181fae002551f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:f1fd6b90ac82c91578fabea5cba17be5c87bd90b17c393720cded02c5d0dd408
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:c67849a2be85d5d779d819e05c03d7be1c242bf2ccf241a8280b5f0d5b942206
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:28561ea5f1fac601a1c8162ce394fb58b4537014cd73f7ed058b16e1799d54e6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:ece32d2851bbdcce07a25ad3c02a8b83f495944e98844a7be5b8aea33b962467
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:3b6e4437dffac77dd663b3afd49b0b4706911382db23b9ec23a9921b8a3112c8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:5540f264829e39fa516b132b40a212cd02218a0cb6978abe21c77019849d0707
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:be5d7f68ad9102f84fb10d12e1793000d6df4979a58d48592e0ea03f78d72357
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:3ebefff6e6f41755e432962915cf6ecf6db107103f919ca8696ad5e3ab047076