Sign inSign up
Gradle

dhi.io/gradle

Gradle 9.x JDK 21.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

9-jdk21-alpine-dev, 9-jdk21-alpine3.24-dev, 9.7-jdk21-alpine-dev, 9.7-jdk21-alpine3.24-dev, 9.7.1-r1-jdk21-alpine-dev, 9.7.1-r1-jdk21-alpine3.24-dev

Index digest:

sha256:0fb4c1c5b3bf5b1a4d9a5af68f467ed6d830dd027d01e14c4e70435dfedb7c7b

Manifest digest:

sha256:d1a83848cc563ed25b8447108a9a632581aae1b4ef1ec2801fbbf46953f4f27e

Size

332.05 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/gradle:9-jdk21-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/gradle:9-jdk21-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/gradle@sha256:3bd826c17dfaf6856f4969670b1cd01865c57cc16c7f52158f8cf137b3a13d39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/gradle@sha256:8240a666b97f9d68b3ceb09474ec213c65bd3949e262116a9d6d6bf3215941d7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/gradle@sha256:6261235c70b5a2c9950d79e3e346632cccb5bc1a50cad592338ac94956fda970
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/gradle@sha256:954b2b0a8f8cd83efee08a2e0a376af8e1050d90ffd5e98165db857122421be2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/gradle@sha256:4e8750241cd18a7acd3c42852035529f7f53c350394bbd1eb2921112dd9218ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/gradle@sha256:8d79541bb6039bbd139c1074621745c006571b4ecec193f8c621d6dbb057e7cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/gradle@sha256:df4e74e644174a18760c17401bf8533a87b3ad544b7c03cb9ef0a6693991457c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/gradle@sha256:c593e5b2aa7b7c0ec160045dff0b621926bc352b830e27805cc95d380d849d74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/gradle@sha256:90d4d62d0c7f9e71d5f15d708259c2e2fca3284afd252c0a05c5b6fe0d908808
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/gradle@sha256:dc5805eff4cc325d5f7698c18a5f5066958a6dcafc754f8fc5e1af71fe74342a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/gradle@sha256:385988d0d243267d6b6adbdba9af4238cffd75f4d4395de95647c1486eaac911
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/gradle@sha256:47ea609eabb2b92985b74d55b761e98532ad63b7d2561a5fa81454947f5164b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/gradle@sha256:676e3646b44ee8ee26c45326365c392e35dd5624d2344e6d9282d2a35dbdcdb0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/gradle@sha256:e1ba91db430e10e8e4cd578651a50508e67d3102087507363544ebe17f44b000