Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

11-jdk-alpine3.23-fips-dev, 11.0-jdk-alpine3.23-fips-dev, 11.0.32-jdk-alpine3.23-fips-dev, 11.0.32.1-jdk-alpine3.23-fips-dev

Index digest:

sha256:d2b1961d7d1bdb5d4ad8871a44502d306ff7f3980f400b60d86e9cbe2638df51

Manifest digest:

sha256:bde966c75d973e5965f61ef3c090b49d170f59e83ccae4add9ab7abede6fc3a3

Size

184.15 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-jdk-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-jdk-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:5c737385e02f05bdf988efd922b65df22f009c3614ae2c4602b7ed0c2d5974e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:271c04bcdc82f0d7ff92264a42eb50dd1baf95aa22ffc6aabcb3541f78cc7c4b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:ca82ca2f2826af5d16540aa79818e01fe1783b782d20466b17d2d9a5a736c76c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:59bdba44bece5d5ac5bbf4939cf3d828684449460e137f96327cb9c07a151a27
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:a711a7cb1b74efdaec7aefa9a96a1aa9f78fa55b2e5717e13512b6d7bf07ed2a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:86d7823cb786382f05daf52b219f0977522925ecfe073c408e9029892a7a9540
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:21b5d0baa2e54afaa17af06251d13de7c63d7f80bbcbab4501d3dd87968abcea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:c01156b10453c5710f0b278d763e454dbf8b4ac7e1a57b024ce59e2ebf0b3ea1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:27aa270969388e4362dd8efd3184c95658d98f8b1db3e3a6b1957748d814b540
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:4b5f8a1b4db7783fd856a66628d5b3b290781592e4942f633ee40bc1e610e070
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:6cc7e3750ff9b9cfd72a1c574480fb17240f665010e8ea14eed312e9f59e6dd7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:ec3e3848736988782dfacb9175cd5a46f3f06f4d6d9ead81b26b846749c0d0a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:32803cea0947cea23117ebbc9982debd62ee3d6ba49bd2bef05536276c14a00a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:3c5bce368847bf0142f40cd51b8b21e264f4ad887e107b72fcba244821463a43
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:46cafe35351fe72d23bd80e9549a197f30eadefe4ee59735fab790ec94c1704f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:a1b875ebe81c195635833f9c970aae6bae429c1822235dc5d985192ddf9b407c