Sign inSign up
Gradle

dhi.io/gradle

Gradle 8.x JDK 11.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-jdk11-alpine3.23-dev, 8.14-jdk11-alpine3.23-dev, 8.14.5-r8-jdk11-alpine3.23-dev

Index digest:

sha256:d288746fcddc0c1dcd62d56349787cca3b7b5d409f002cd8cddb2c27fe901df5

Manifest digest:

sha256:979f4d7fe0553aaa9393015d2bd634ea64cb83b9658abc3cb7432f343b8f4206

Size

307.84 MB

Last pushed

1 day ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:8-jdk11-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:8-jdk11-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:f7319ad5a4f29a460319ef867d3e56d56a141d837425048e7cb51cec93f459dc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:a66ef8f164c1f1c38e10a135010e770befc17b8dde16a0bcc375da317339c741
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:5e5a8d2842cf14e55d87d98a9a55ba2c8f5c55f05e684b13787545a9971d0c07
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:8bb07fd44929edda2d2cb9ec92acf9fefeec6490abdddc7c33495ffdc7db6008
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gradle@sha256:61c99ca6166dd32493950f05af098d43ae4adbe4031df03ef61047b55889fb97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:ad93a1027cf5f2f93ae968105bae6786716f5c5b97c15f1362d0b3562592650d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:13c6d4a46bb7498d5e68233eaeb8a0d63b0c85a343d77388b9239bc719d62427
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:6c8ffec0f5f5f134dcdad0b0db2930ebbb447f25a25f1f06e65a70c154836f80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:cee2d8eb0ed6fd80b3a287291c038e8dad38e26c87bc344a56d73245f8d5fe1e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:160a1c46ee4d1467cf1d4afc473f298eeb3502ff9768e85e69fedc6f230772ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:567c5270b9f1b384779619bca5d5b40906e70400775800768a5eba7d0e1f8d0c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:8e14490bbe926d06520315dc397dad67bd7eb3e8248e78e35ffc61b9f00f55b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:4f5f22a6d978dd03db90cd7d8237bfa5a8db3dc34564ba97182e2eef2da9ab67
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:c8a5b8083e9730471e4ac87ab11d481a96fe6900137f298e422414e133942e66
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:726f1252ef1644a9bb4fd5d2401870e05fd74ba8fb55741b83ba67f91895d290