Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (dev)

CIS
linux/amd64
alpine 3.23
Tags:

8-jdk-alpine3.23-dev, 8.504-jdk-alpine3.23-dev, 8.504.01-jdk-alpine3.23-dev

Index digest:

sha256:4f31d29dc1019db5da035f7f2c60f940e3764b3af0577b9cba896ba7846cfdf8

Manifest digest:

sha256:aaa5bcf29f0cfa8abf4bae65447e3ec6fef882bf896c597457dc9dba876477d7

Size

91.92 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:0c3c32c3beb4ce3dd33bbebc16c38ead0e4e8271a24c2b7094042a915a691dd8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:1b93cbf1b7c53d66afac337b463e571dd1e8ef6d850287c2834c97951b70428e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:2591f7aa3d75b15f26dbb394b5939106acb2b9edf178fa7be7dff100d5ed88d1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:0c94c9907756ebcd8b8c2d87e7b0a576d6d93fbdf4894304a2b8dff872af0e19
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:5337c36b83e3af1a7b3ec74461dfb9c01626f5a7367465507c56fe3b701226ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:4c3b9eaed3389c5d91fb673e22de4e6bc9fbf4f183bcd01a35a1855be455b8cb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:28e2a48099e8a28bdd862c2bdca85a80c998cc7c79841f69286fd2c4d8e847f3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:4a7c4962672c40a30d555a098d3d9cc1404523de3029b1292872b30ed6ced493
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:a392407e91b89642a9957d2c308436106119fb329ab8e28c8618be9985ff3711
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:25367b5055d5954b8dfe96ec1c35017031fdebd9a8f01545b59f6e2a71e5b559
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:8ad85c5dcd7c01b812eff9495826c5693a8dae4f2121a94815f5a3783ceba081
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:757f79d585ab0797f1267a73c33603c6bb57d1042cb55aaeea43117041e30991
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:d9125290e0434fef037b818c5f825a8f37cc67c29a5fcb0f5a95b0c89d53e07c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:b91fd632c5cc648eb4d06bf3dc1907cc62575699232a36a5bbc7754c77409e02