Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

9-jdk21-alpine3.23-dev, 9.8-jdk21-alpine3.23-dev, 9.8.0-r1-jdk21-alpine3.23-dev

Index digest:

sha256:6bc8682ce1a792e551b298a4a6a6908acb481227765aa9ae6fd77f2ea5bbf30b

Manifest digest:

sha256:64f83ac9a093e778c566310137ddffaba94b9e9adbe40ff26edab6fe0b1eb143

Size

332.24 MB

Last pushed

3 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:0075bccc80214c6305ef6343cd3e7ab2d0980080200ed0486dbf12c8b01a0b71
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:0b32d52b5918df50619a7fe7acb4bc91ff725fec635613a7460cc6963ad8af73
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:738ade1b4a86db4b8eba105fceec7dabd22928b1622332033f4c124fa8c02045
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:54d2597c4ef10b721fe17f1baa38f6a9cc2974d5aac192f4ae534cbe4caf9989
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:3f76a6ee9d0985e45e1c2fbe5378100c92a01e344f50c45fe2f120f062173ae5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:16290d7181c315b0a9a1c37ccc8eaaef8cf22161d05d3e47f2d09ea3db4b2883
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:e4abcc0d866abbd7be7671fe55a8b4b5a7dc0796c0e1af4d2fa0c9f66a9a403d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:46bd22e069f306d7334a9a7f9bba501faac6bab0e1f4d9bf76c52384677dc92a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:5d244438664cc1db8198c7538cdebce81df5066fd7a0bf1aa8e59c24ea212e79
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:2269fc023a55333bdce3d30038a171ddaae50029bcc21a3879ad4730faca62f1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:8b60b9487e8d4769efb1774422cf03b639a139bb9fe95fb8fe7396e8a0066258
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:a310b76a570f13be0dd6abdfd69f819b783359827769a51fbed4fc59b436066d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:974d65bf532b4ef2d08233a6c1481f786fa5bfc7d87717aa54de9ea9a9b4caa4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:9385b6187ac8d14e21be7540aed6fbad469a30c8ec6e49eb5fbea6522e6db0db