Sign inSign up
Maven

dhi.io/maven

Maven 3.x JDK 25.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

3-jdk25-alpine3.23-dev, 3.10-jdk25-alpine3.23-dev, 3.10.0-r0-jdk25-alpine3.23-dev

Index digest:

sha256:20516e351aca5e4b09dfc289230bdb3ea1cb704238fc8a6f88c36769244e5332

Manifest digest:

sha256:fe70e345c75e561bc6f2be56f1e095bf29e6a6fa81ee1b849bb942fdd4e5f09b

Size

131.56 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/maven:3-jdk25-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/maven:3-jdk25-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/maven@sha256:a33cbe3ee590747c3b0d2ae921e74f8e849502105a397b1dccfba5e7173a7e0c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/maven@sha256:722790ffb39576306c5862d0492710f776bf5af70333e258ef0e152112e57aba
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/maven@sha256:0b49905f2dc880652c2bc4f2d09ae25c31450464e25b6ef4023927ee921d05b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/maven@sha256:fa40c20b073f0246477c3b16bb0e513c06bb8811a5e9f9fd3c9e52896675034e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/maven@sha256:8add64ef6384841aa9abc88ea7ecb12fde2aa5df0af9c2507704aeb9990cb34d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/maven@sha256:60af6f07574fc0ba7992cd813d31c13d5c746624e80ed6b6be6774d0e7a591ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/maven@sha256:687b0a5fd44998fcdab6430cd1aac86a4cbce492ba634a597d32c940eddb527f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/maven@sha256:2965b865fa6a3d4b3cf43b2b3124abcc0cbd93cc5cfaf3d970a4c182ae570573
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/maven@sha256:9451be01f3fb77a2a15d2d0d2fe5ec580f7da2c701013f6aa6d0365297fcc013
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/maven@sha256:7120053abb5db63cf18c5625c54878b87d0c3f31591ce3a3a4bbb87526f277a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/maven@sha256:e2fa805e6ecb0fbde60768207e05383080e2ce0015618cca845db883e46dc07e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/maven@sha256:7412e9af124acaf60b28824febfb8d0d5255345bae9229fae0957bfcf7af0957
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/maven@sha256:114eb0c1f1c8fe7d562e9aced4ab838797947b0f8c3ad3435b78a65c93d52c95
SPDX SBOMhttps://spdx.dev/Documentdhi.io/maven@sha256:2df19f72349ae90538530b5a0bdeb53fe985eb9ebc328615fc674eebcca15bce