Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

8-jdk-alpine3.23-fips-dev, 8.504-jdk-alpine3.23-fips-dev, 8.504.01-jdk-alpine3.23-fips-dev

Index digest:

sha256:01f7cd4eced0a531bf01c278811608b3142a2067c7718c88500251d22e20ea77

Manifest digest:

sha256:2bd23346ce4511d713a76fd9c26c2739adbe418fd8569b4bf2616210c5f2542b

Size

102.46 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:5ec7b2028eae7aa63f04556290159fdbf0edb6e8c592bcaef2b73bce28348c51
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:72e28d9f4cac294bfdd1abbd04246309b0ba50848100ed94efce8d25100f27a4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:33b4023df53282a7fc758ecbfb24322793aee05da0ecd3eaf61e7fdda614a517
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:c055a60263c85237602ce22e04d4a0e613732db74c6339069ef2bb612e53f214
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:61f69009a3ec82d568e851d20c25a870c891a0fb94d88dfd5be6b0ddb1c037cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:bd10ba3cc7af9355210c4ddb3e79b77c72ab7ecbd2a2b58f3947e6e8d6f661d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:047f8bd0b4557f71f546e0d16f6d87119038dc972fabaa542e03cb10ef97ca26
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:c895c4bf5d375de37b3cb83402e6b0d915d5f93877937b79823972ebde3b2f1a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:8fea996c26665b29102784e6fecb40c5c4d66e0e6e686108a82e13a9866e7d22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:1e1b444cc7c5a66600d0a1b9670c3ead837eccf19147ef5c9dcf8d1f6262660e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:c9633975a7b935a8e7b2c6a36505cb55b3e41f5a613b28b528e980baa9bf04d8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:853aea061db629c0d0f854ff39fda9514b86244d5e65147d01d3dc4511a8f65e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:36fe2928e8843cea7f6ab3f0ca456fb7bf099645da807a87a3e6b8d222c7390d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:4ffb952ecf82bbf53f3f4ce47f5aff4c3d274d811fe355b4c2f20a89a47c1e60
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:0f35b6f376f91f46767c7a7eebb42d7544e3c1c2e67d5b60c8223f0cbdec5b97
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:52ff098919345992c01fed1effaf205d6f07c4f377751fafc293d05897db5cf3