Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 17.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9-jdk17-alpine-dev, 9-jdk17-alpine3.24-dev, 9.8-jdk17-alpine-dev, 9.8-jdk17-alpine3.24-dev, 9.8.0-r1-jdk17-alpine-dev, 9.8.0-r1-jdk17-alpine3.24-dev

Index digest:

sha256:b26021cc0fcdd97ab9035f926f32bbaf34da8c5539eb17b33bc38481a5642e2b

Manifest digest:

sha256:577fb0edeca5887b06bc35e14d38be8215c9d562573129dcbc09dc1eaebecf78

Size

320.35 MB

Last pushed

8 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk17-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk17-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:47cd4622c1382ef429d380e20a502fa39d7b7c3ba90a2a7d996ce6746bd04135
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:d0a39759479a548afc702ddf73dff6472aefd5ffdd5861da85e700ae32f6a4bc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:31ff620c75a3fae242b9df97c70d256bfc1ad76613e7ea89f902ee2e858c399c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:4cc75c5e868478cbdeaef6ad59d2ddffaa7b397f155c8de40bcc0786fb8239ed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:af6e7cda41cb38554e9cc82ad296567387ca0f083fb52aec87f6b71e4aa6ef00
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:db29ad6cfe7537d71c77b401ec1af9f078317ba630bffad5e57520d920325083
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:68547e3f5a750db5184e09921c172a8af171e39a855a9766ba7eaff85f6fca87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:34cb7e740e7bacda5c9d4d8c610d90bb9c52cf1d633eee7b4230457406c31803
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:11fc91cc51493ebbd3e74c5b03093a659a45e7fcca8c0f43665e96c2ff1aa8cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:b2ac0fe4974f651194728e4c989652e5354dc5de7515106c60b237086d6274fc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:2d3b0b5fa15035e9ecc2548bbfeb174b10066004e2c3fce7af2aeae68fe8ccad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:9722cf987ca517479506a19edb6c47544337694e089a142759f2ed370b7b8b52
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:dfd12ebcd8322b679f33089f5b818b50688ad9db13ba8db0e4dd0ff1687cdfb5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:ee961f059bc28f0be1bbf80f0936eb9279d950ee39f60e8e76e8f0ec243ceac4