Sign inSign up
Maven

dhi.io/maven

Maven 3.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

3-jdk21-alpine-dev, 3-jdk21-alpine3.24-dev, 3.9-jdk21-alpine-dev, 3.9-jdk21-alpine3.24-dev, 3.9.16-r0-jdk21-alpine-dev, 3.9.16-r0-jdk21-alpine3.24-dev

Index digest:

sha256:e6021fc7425dab8bbceaa5daefc413c47944b90492ea3d8545c3e6d4149e57ef

Manifest digest:

sha256:bc14ae06e4cb8edf7d55da019f68a87a7e00cd7eeaee33f0e5950aa540af2f33

Size

193.66 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/maven:3-jdk21-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/maven:3-jdk21-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/maven@sha256:a2e45ab8bd8492a79427c995dca503ce5c8db260b3797038c4d16d76b4940cee
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/maven@sha256:078caa3531f138fd85477eef8d960415251350efd256e105b68abbd92fe05185
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/maven@sha256:8a3398172749ef76706f0b413616c1b3540d2d58b7a3eba100c9f717e9523e37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/maven@sha256:bf90e5b7c10bab1847bf020e3b8c251c92a7e25c0f894255a6a3cfae5abe9c93
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/maven@sha256:7009aab1e8b496ade5a304e8fba2cc21fe745166e69207cf332dd04e34c93a24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/maven@sha256:e15e77ca5deaf0e0f624907e6be3ed426a75f2ccdde7dd5b0308b9b041beaf11
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/maven@sha256:4e82101170b19525642f67893cbe6416f777409e800ba68a5f4a6dc86a9b6442
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/maven@sha256:27288346932600e56e3b1a6e5248ec32238ad805d02a58fb628c9db9c3c1fdc3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/maven@sha256:a775b290cf2de64110152550ce641ada5365c92552b1baae9840ae81a7cf6f69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/maven@sha256:32d11724d96c9811cfac45a4a76897bcd877e7c622557881580d65e0d8cf51cd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/maven@sha256:f05c179487a3e518fd15b066f95489687e65035d8c087a35b814252a2081ff27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/maven@sha256:833023fa98d211d129c46800ddac001220fba4901b39886d1eb632067e09392c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/maven@sha256:c085bbf646986cb890c6cf86bef4eff34de1e70f7323ec496ca43ae50e2e8b48
SPDX SBOMhttps://spdx.dev/Documentdhi.io/maven@sha256:91dedf3427719fc5b786c8cb1b6a85fa17b7cfe7859c4dcc535c2c17148922f6