Skip to content
QuenchWorks

gradle

Runtime · Build tool · standard · v9.6.1

C 7nonrootcosign signedSPDX SBOMSLSA provenanceamd64 · arm64

JDK base image with Gradle, used as the build stage for Gradle projects; run the resulting jar on jre. Line 9.

Signed
cosign keyless
SBOM
SPDX, on digest
Provenance
SLSA build
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Image size
239.1 MB
Last rebuilt
2026-07-09

Security report (Trivy)

C· 43/1007 fixable · rebuild clears them

Vulnerability detail

gradle 9.6.1 · 7 CVE
CVESeverityPackageInstalledFixed inTitle
CVE-2026-46968MEDIUMopenjdk-2121.0.11-r321.0.12-r0openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
CVE-2026-46968MEDIUMopenjdk-21-default-jdk21.0.11-r321.0.12-r0openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
CVE-2026-47021MEDIUMopenjdk-2121.0.11-r321.0.12-r0openjdk: Enhance XBM image support (Oracle CPU 2026-07)
CVE-2026-47021MEDIUMopenjdk-21-default-jdk21.0.11-r321.0.12-r0openjdk: Enhance XBM image support (Oracle CPU 2026-07)
CVE-2026-71497MEDIUMorg.jsoup:jsoup1.15.31.23.1org.jsoup/jsoup: jsoup: Cross-site scripting via malformed HTML tag names
CVE-2026-47010LOWopenjdk-2121.0.11-r321.0.12-r0openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
CVE-2026-47010LOWopenjdk-21-default-jdk21.0.11-r321.0.12-r0openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
0
Critical
0
High
5
Medium
2
Low
0
Unknown

Security report (Trivy) · gradle 9.6.1

Published versions

1 tag

Each tag is a multi-arch index (amd64 + arm64) pinned by digest. Tagged by version, never :latest.

VersionSizePublishedDigest
9.6.1latest239.1 MB2026-07-09sha256:113a7ff470c6…

Use it as a base image

Reference it in the FROM line of your Dockerfile. Nonroot, read-only root filesystem, built for amd64 and arm64.

FROM ghcr.io/quenchworks/images/gradle:9.6.1

Or pull it directly

docker pull ghcr.io/quenchworks/images/gradle:9.6.1
Version line
9.6.1
Latest line
9.6.1
Architectures
amd64, arm64
Runs as
nonroot (uid 1001)
Root filesystem
read-only
License
Apache-2.0

Verify the supply chain

This image is cosign-signed and carries an SPDX SBOM and a SLSA build-provenance attestation on the same digest. Check all three before you build on it:

# 1. signature — built and signed by QuenchWorks CI
cosign verify ghcr.io/quenchworks/images/gradle:9.6.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. SLSA build provenance — which workflow built it, from what
cosign verify-attestation --type https://slsa.dev/provenance/v1 ghcr.io/quenchworks/images/gradle:9.6.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 3. SPDX SBOM — the package inventory
cosign verify-attestation --type https://spdx.dev/Document/v2.3 ghcr.io/quenchworks/images/gradle:9.6.1 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

See the SBOM & provenance guide for reading the SBOM and using these checks in CI.

Best-practice Dockerfile for 9.6.1

Build the jar with the gradle image (Gradle user home under /tmp for the read-only rootfs), then run it on the slim jre base. The daemon is disabled so the build is reproducible.

ghcr.io/quenchworks/images/gradle:9.6.1239.1 MBrebuilt 30 days ago
# Build stage: build the jar with Gradle.
FROM ghcr.io/quenchworks/images/gradle:9.6.1 AS build
USER root
WORKDIR /app
ENV GRADLE_USER_HOME=/tmp/gradle
COPY build.gradle.kts settings.gradle.kts ./
RUN ["gradle", "--no-daemon", "dependencies"]
COPY src ./src
RUN ["gradle", "--no-daemon", "-x", "test", "bootJar"]
# Runtime stage: run the jar on the slim JRE base, nonroot.
FROM ghcr.io/quenchworks/images/jre:25.0.4 AS runtime
WORKDIR /app
COPY --from=build /app/build/libs/*.jar /app/app.jar
USER 1001
EXPOSE 8080
ENTRYPOINT ["java", "-Djava.io.tmpdir=/tmp", "-jar", "/app/app.jar"]

This Dockerfile is pinned to the 9.6.1 line. For the line-by-line walkthrough and ecosystem variants (npm/Yarn, pip/uv/Poetry, Maven/Gradle), see the Build a Java appguide.

Upstream project: https://gradle.org