Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.12, 1.12-debian, 1.12-debian13, 1.12.6, 1.12.6-debian, 1.12.6-debian13

Index digest:

sha256:b06381944d143e1858d251701b601304716a74d763f3f81cb608b1c7a0a5891f

Manifest digest:

sha256:668c08183bf53b764b3b2862b1f1d7b043f2612cd3690ef40f3f814b24090d78

Size

111.08 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:1314861226b27866bdbd68059c8fe96a3f24e088b35b91fb7232051bdde7736c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:d58a94ff3701a5926c3cc5ad9db40870642bd9eab40489f4b6582d0a537f9d4e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:ceee6d2dfef1988c3e27c8df89b0539ca6e3e7312dfb1ba381de6a67914e2162
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:878a9d1b74cf776623ed242e654a4aa5b5ca59aa2f5cea788b00523970becdc2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:976ec886500873712f743bdde4e5f65711c840a115b8eb86d65e029082946924
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:a2ba40622d1e7348714e34941a97f253bbe8310b9ff033042f8352a3bf3e6b0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:ef20e2e6fd8f6e05310c8ffcf6ffb41679e64d4f7f1ee86125adf251c28e2404
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:8fe83edd7b52b70e0aeceb16634b51a05cd22ba31d9d7c881e7fa72b8fe41dfe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:757075bd8fdcbe026876deb010a24c117d49347d7beb8bb515434b83cae69648
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:c6ac0965c77934e4be7b8a0c4a86ceaf91295f5a5db118d4e7f70c3cc9883d6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:737d2b467828c83557ebec1787cffaf2a5ef5bf24879127f9440cefc1887a6d6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:0e628a857c14b40319aa29d3af8855317f4f1f9a8414d375b12c73246a7d2ec6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:c05acbce7b5af93772c78e3e0fb8daf622038d747fcf985c0fe70539db9d8a27
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:f0475f575dd152c8ea6c5041c9093a4136a6d6c1478efb92519644df8a375ab7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:f468a00399c00654a6fdb923cec0bd900495acbeaf8859ced16677497cacf642