Sign inSign up
Gradle

dhi.io/gradle

Gradle 8.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-jdk21-alpine3.23-dev, 8.14-jdk21-alpine3.23-dev, 8.14.5-r8-jdk21-alpine3.23-dev

Index digest:

sha256:342fe694138f247451601e8be77e23a9efc25b08bb243ec0e73ed64ad3df38a3

Manifest digest:

sha256:0574b2bd3553a163fa4c555eb823014c517ccc4192d5b7ffdfe7b80ce200049a

Size

318.67 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:8-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:8-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:ecd73a3abcbccf5e889efd8ccf0c9347d3bc13cb6c292a3ed44658a74aef1608
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:f6e5aa2b894ea45919267f55f4f746d1b9344b3486aec8ed0adff3e693e1e198
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:14fc34ab7c83cc352c144cf789da3a922485bfea8541b9825e82e577ea7f2e63
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:88cac7dcda3dc8c15b6a48bc5f4f214b23998ce9f97b0d2c395c4abc6c87176a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gradle@sha256:f64effb732b06812a9934b7a7e38b2d8a9b1bb657e0dfec74104bfb9616c425b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:1ea7c2417645cdcf052cb36cbec147976e19a05ce1c7bddd462e8f52d5bdf1ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:f40423169487f5c56402b0bfbb96baf440a714018babb11f753211a89c579839
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:31d55587b650c6d5427082cdd148e09e57738aa414ba46a59171cf4b98094f91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:d32fb6bbc7afbb160863c057134ef449c0944a6b31f2969c3ee30502e7567364
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:516e3edc50bdfa251ff95e82c6025d993992fa8196d51282bc8b23aa0c1e50b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:8bc0a1243fa4c8f766a8bda7466f1a3ecadf5dca925e75b441bd44ad69d9d43d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:3cd220d57ab9b6c29004c24b1864c8c8c6b712e5aea8b674d53d0939b8e6b8c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:f72a5b2fdea7ffbc35145d9fef983f36c7360bdfd9766e3fd2e4b45a7cd6c3a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:435bb46c67df3ac09059b9fcba3b932808123f192aef4e41748fdc86637e0fc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:0d0eac947ce8797d53f438a9618d0a0e6ad004ff76e095e1b583f0b1dbe1a4d1