Sign inSign up
Gradle

dhi.io/gradle

Gradle 8.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-jdk21-alpine3.23-dev, 8.14-jdk21-alpine3.23-dev, 8.14.5-r8-jdk21-alpine3.23-dev

Index digest:

sha256:b58da553654e75c7ca248c77409163f73f2776c3fea2f97b8fa09f3312cea6ff

Manifest digest:

sha256:194e9c5cc42b3a5f146d8f9cef2af3e38961a4660ea345ab7e6125cf809de636

Size

318.67 MB

Last pushed

2 days ago

Vulnerabilities

1
1
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:8-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:8-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:5e341024af1b7724e2689bc9b9d116a964cf41d88ee7838cd33a4cada09ac589
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:6cecfb061c3af3427c79b28b2fdc2fa3778657cb80a37f5f44b35817d8a4f7ca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:4b192b5878eada049bcae5458e424bd5822af41ad771cf19d4437fb566239102
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:1d71d45abec3212e1cf9f539c0480da1c16839ac6aa64192e998034f94efcd3b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gradle@sha256:4f61944ba6aa29e1019ffb2618e7d931a15659f90083b1ffa357418a4eee3b4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:b8646ca570bde0b038acc54c09c998fa773d311d31b9c0c9190d894af4acb686
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:a32656079a7fddda28c9786007d70ce403608aa91af58ce982e563c724d6165b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:179fc87374b295db361abf0e46ec1ab7da659e83c72bf26f21a5882c92eba5fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:dc214cfb1c61bb80bec141756597110dce473e4a616331e0662846f0018bc1ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:960190149be2ca5789449b7625db3d45b9b4626cc8545ec25075af4bab39aa6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:f9e1dd66096202cceef4288170e6fa5439ce304c444d965de5cc2af1a575e705
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:dfca989ecdb5f5c524be5d9d9bc0af62a293349f619999b8d18a665e54bf62ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:f35709e8d3e1125dd0021ea621b02b199c40e1eb11d056e5b3d54a7c576f2be0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:56a986553e8ce2608d4d5ada209f200f298c4e8923a45d6dad7dbe547344273b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:23dc603d6d718772a336acb03b2adf0106fdb184a4d67134defaac786231d70b