Sign inSign up
Clojure

dhi.io/clojure

Clojure 1.12.x (tools-deps, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-tools-deps-fips-dev, 1-debian13-tools-deps-fips-dev, 1-tools-deps-fips-dev, 1.12-debian-tools-deps-fips-dev, 1.12-debian13-tools-deps-fips-dev, 1.12-tools-deps-fips-dev, 1.12.6-debian-tools-deps-fips-dev, 1.12.6-debian13-tools-deps-fips-dev, 1.12.6-tools-deps-fips-dev

Index digest:

sha256:e96f4789697a02bfc97b9025a780e3ba5d5ec4adf38cdf54c0a32908e3fbd13e

Manifest digest:

sha256:79d766fae8a646b3c6aa10b188fa6abbf990c6bb520dea0614a6397d7eae50db

Size

197.30 MB

Last pushed

23 hours ago

Vulnerabilities

1
3
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/clojure:1-debian-tools-deps-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/clojure:1-debian-tools-deps-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/clojure@sha256:93d7256a58c33a454f51e86ef87c451535865478010663d5f99ba08df13d332e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/clojure@sha256:29ca95e9de4e5d1e65cd5499bc134ed419f67f209019cedf604f15154ceedcd0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/clojure@sha256:0f1669dbeed36a36f07af7f35e1f3f511b73d38f3b2fe83c8a6688fe5056b738
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/clojure@sha256:71c8a85071a5661bc23ee92f14a56c2ad26669b780821f094b8a5eceb265ef6b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/clojure@sha256:d7f79ffa55e565e96cc216dc321b2e6d33a8497b2cccee1ec43f955546b05ce5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/clojure@sha256:183081f140a1dddbe2aaf50c52483af36d3bcffeac9b1c457e15425ab0ca4e3e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/clojure@sha256:a0facdd375cea0d1fe47acb63c7e885103bee363309484f9949fb2643b516785
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/clojure@sha256:0494b3935e51dd24ccea7f813329a48a6ce100510c3c35f4fac5d3d32d7b2c65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/clojure@sha256:1b26742d2b5c2eff405d06c91cbf733247ef985849e65e381f4ec757de2f3082
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/clojure@sha256:28fff190a6377fe332349f148f343978694e82616985312f564266d03d1645c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/clojure@sha256:cd7643da32829172d9103b1ed0e42884b615ce1e0a98241ff9e8eaaf9d2198ad
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/clojure@sha256:2ce80a4efc8bbcacc876a67f7a6ded1f8121ee1193dbf15d7210022f3d373ca0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/clojure@sha256:49ea4d6b3111e615a6da70013cd5a32d89502f6a8df3fc879310d1342e07abd8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/clojure@sha256:de25a96bfebf98457e78ec6bd98d8040ff689d89a135913e99d8cbb1000d871b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/clojure@sha256:a9eac4e9af41653a0858e3e0be53f35944b920b58ad309c8a5f1c69e1b4cd0cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/clojure@sha256:985d286cc3e8b4551bdd182e2e9e4197fbf0605d2a4418778d6ed2ab4c770337
SPDX SBOMhttps://spdx.dev/Documentdhi.io/clojure@sha256:ebb8e2cbd656181d21778b433c7211d2ca4a6972f1e72d0e3573b82efa185afe