Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9-jdk21-alpine-dev, 9-jdk21-alpine3.24-dev, 9.8-jdk21-alpine-dev, 9.8-jdk21-alpine3.24-dev, 9.8.0-r1-jdk21-alpine-dev, 9.8.0-r1-jdk21-alpine3.24-dev

Index digest:

sha256:af92a4b213811cba487f7e8555eaf3b96596d3e73fe88285a8c3a1cbd3343876

Manifest digest:

sha256:bc46dc772100f883bd81d5d28fd366ea9a5979d16100bab0601e4e0867ec01da

Size

332.21 MB

Last pushed

4 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk21-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk21-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:4d154245cec64c8cc7fb491eec774805c0229dc9333e719cc2536edee86fe55a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:361d76e0ef262b06660702de9e8fcf581df340b2089ef2d473cc1ce816973f84
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:29d4b83616fb7f53b50beb7e42179f4de77fa447b83f5ddfc0797d375621b84f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:aeb379ef985cb03742029049e6da1ece36cddeda7cb23c2286b102843cacdbe9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:e5303f3cf5736795fe896e7f6fd53e069f5bf1052acee9d0c28fb81ec3bea464
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:f0e83b5dadd9a476fd6ebf83f3c8effb4ec8463bc1128298df1bb9a0d5710d50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:fafd3b1fcc4f42da449c9f39ee08d8307ac0cbfe72fd95ec41838d61c185648e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:50e77585066f522d3668c81091f96cffa242bed0e4aff1c990004a58cbaad26e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:ee4ef6d4dd17829b2172fa687ad68f64aee16d56bbd7ab58e5e0f7f428abee42
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:006e7751656483e18eb7dc4123de0d9c72a3cd92db8cc8fa977efc22cf67360c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:f2623ac1aee66c6a4101a69391c0db3755a6a2fc84ab80b9e215c0f557b2ec6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:172d902084b4d763668607e3115d1e968fe8f7aafb0b14a335e6504654cce8e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:7455ff89ee6a35c865c154db9a10dd6edcb88d37a9851c6db1c5b6cd10ebaede
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:b11165d77381bb4413c486ce2f3448e0961e58073b687a9da112527da6061c5b