Sign inSign up
Gradle

dhi.io/gradle

Gradle 8.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-jdk21-alpine3.23-dev, 8.14-jdk21-alpine3.23-dev, 8.14.5-r8-jdk21-alpine3.23-dev

Index digest:

sha256:b58da553654e75c7ca248c77409163f73f2776c3fea2f97b8fa09f3312cea6ff

Manifest digest:

sha256:194e9c5cc42b3a5f146d8f9cef2af3e38961a4660ea345ab7e6125cf809de636

Size

318.67 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:8-jdk21-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:8-jdk21-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:5e341024af1b7724e2689bc9b9d116a964cf41d88ee7838cd33a4cada09ac589
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:64e089af9ae97bda8b3c9ed1eb72af62c8d55b92c3094485de82fe1d00cb46d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:97886af8c355a92e4ad6d8ac69fbce7ed8f0d6b8bde58de233bd2fbd1c0322bb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:bdc59e59ca65069a9118492661003830597c6d64c8746bfb42e57922d5a19ff6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/gradle@sha256:4f61944ba6aa29e1019ffb2618e7d931a15659f90083b1ffa357418a4eee3b4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:b8646ca570bde0b038acc54c09c998fa773d311d31b9c0c9190d894af4acb686
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:a32656079a7fddda28c9786007d70ce403608aa91af58ce982e563c724d6165b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:179fc87374b295db361abf0e46ec1ab7da659e83c72bf26f21a5882c92eba5fc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:49aeaf67f314bd727982073c5b052b721871b6fb80e4158c6f06f24594c0cb84
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:b747a2ff27519fadf5976abd606998d21fd1bf30d90bd6d2da84c8d8cd3faa28
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:22d0e0eb2b05ed2b2ba9a975091a60c094bbc10683bb0dfed39b541e32e65694
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:dfca989ecdb5f5c524be5d9d9bc0af62a293349f619999b8d18a665e54bf62ec
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:f35709e8d3e1125dd0021ea621b02b199c40e1eb11d056e5b3d54a7c576f2be0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:56a986553e8ce2608d4d5ada209f200f298c4e8923a45d6dad7dbe547344273b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:23dc603d6d718772a336acb03b2adf0106fdb184a4d67134defaac786231d70b