Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 17.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

9-jdk17-alpine3.23-dev, 9.8-jdk17-alpine3.23-dev, 9.8.0-r1-jdk17-alpine3.23-dev

Index digest:

sha256:face48ea6fe38fef1017e18c785a1811a3d3b42b0a20eccee76b5fca544ee11b

Manifest digest:

sha256:935e533f1c8136b78c33e377f46ff054de5200a90e60f2c00944bac66d8a81e1

Size

320.43 MB

Last pushed

15 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk17-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk17-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:20f254e4609cd1ca2571a56990f7dbf4675059565179a395394cbce66229fe7f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:92df540f26fabbb020868173be2741474a9ef52deed54e041f6cfffe1c8206fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:b5ffc5f6b3b0f8f4f6fccbce70e99676f896d7d3070d1929ebc129a948eeb984
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:92d5f0785b108f9a3e61770f8b44e3305aa28493033ba3fad2308b8185abbe7c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:bf0795a84922681851d2cb03adc49a048dc24ace7666df45d10412fee8c53f2c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:5faf5fe0ac7fd1507fc2d298e15307902d92df3c0a2cb6f5be7bc6d238716d90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:200b78c555c450ad8a4b0736b1a5cb4d9b4c8bbae4c6ab3cb92275e5f378174f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:aa6a7cfcbb1a4f259b883d87b876d78f66cbc11befd47b2ee0113bd04ea8c03f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:fff0510c4b4a0792b1c6fd4728fc343a1b1478cb88b8b45ec6958c4ff034eefd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:b65d6b5463da9bb611186d55c76b4a2eed7c120ef58e8440bd494fc8c54ee8c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:7569343522ff8965d71d85fa67b34557286fa26e47595a5e06c727b128149b70
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:5b87c22d81b87a8ac48ddeadae693c932442efdbc9272668815fc04a6179019c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:87968f3bf02585678f745064d8d055c236ea04680496686b86ec3b7c6dce70a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:e11bb1a4b20a7c355248239e3a8cc92a11e3afc21ca64bb8626ecdc35064ee07