Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-jdk-alpine3.23-dev, 17.0-jdk-alpine3.23-dev, 17.0.20-jdk-alpine3.23-dev, 17.0.20.1-jdk-alpine3.23-dev

Index digest:

sha256:b47a1dfa3cde506d4fa8a1878162cdb7dba32dd5739d34f781eb1d289b215f70

Manifest digest:

sha256:5720371794190edaed52a579bcc343073473b3c65d52cdf34c4073527894fde2

Size

173.29 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:d5ae956f87fcd40ff44eeca2d0c00a3d1f9ea5773d1bafda344abab61b25f0cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:da2f64edb7c7f6740b1c104e5f7f84c27f950ec31fc8fd551c558f53e3880f4f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:905e57d47afc9f142c1d58ce8f7d08af004b1e1c74f5b11d29a7103044466846
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:f821530b87f23d063c40f4ffef26f9a917125b22f752c5dd097a3fbd4c8df599
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:730018dc5e698dbfca443b680aeeea07f68184ab0859319937b5dc8cc4709d3b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:0c0f94c218cb564cc5842b40f6ae4fe3b628229b27e3a67ef29bf458cbda4846
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:0ac51eb19c9bbc6b55893a399fe06781199e3d2a239418a5331dc1f46fc5396b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:f6730dd8513a4c7bbf88998c6e6fce7b868c88e73fe52cd04758fa8e64bc50c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:266ee91eee34d07814d452a6ee73bdfc079d3af7420c9e7bb517d999ade28228
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:757dc239aad6dbbe595a2ff1f8b66a9ec675fa7a16ca40dfe09831757ebb6c16
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:069df900d1fdf1277e0982ac92f712c5ee106e79e413203d41346777abaa8984
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:47a4434d3d968ce2082098df8f4337ecabd8a34760df04f3d80285a6083f1093
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5a25a6cfc6e6ce7ff7e6aeaa4690a0095b238f6483cf18e96288211b25653a28
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:ee6ed6b08217b3df39d5b7a49c2a0fc4df36b073f3325be20fba7f2ae7a452e3