Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JRE (dev)

CIS
linux/amd64
alpine 3.23
Tags:

11-alpine3.23-dev, 11.0-alpine3.23-dev, 11.0.32-alpine3.23-dev, 11.0.32.1-alpine3.23-dev

Index digest:

sha256:d713f3ff46fb351dbcb81ddc600e9ae6dc25c04e2717862ab415da6c05537f28

Manifest digest:

sha256:f439da9d7991cb3ab207d16c83207e3d5e161a8077d9d5edf2903e74e4286f88

Size

36.82 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:82b6439808f26560ea660cb34f40b1493d98911f0cbcdde21e4f789b9ec04370
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:0bd4c85dc912a61724d6bdc42ee72bdf8fa4793e7aeb37162ca1fe3de1ffd2d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:0365f0c1cf9b085dde4ad4d69b430ac9ebb14242cd5785b9661716472a84a6d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:5be1c0103a193483a1b32b734710f0f67ef6450da7933e5c612392005098e421
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:da1c3e0d1fea555ad3c2063e80e09657324e93dab9bbebeda7f39171c66ebb57
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:523c54f319027a5c20f982eb13a75cae714bbb16991bc87dfc5ed8fc26221c6f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:d12d249e9297b2cb81d17e56a0ff0e28080f605e1b11db018b24f2fbaf6db321
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:0f43478fb9d0ac957eab262d5ffb73e6dbd2d50abad0464f2da99d61bba9791c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:2aecdff9ceec95f7cf9dd0781bc00d0ee36e4ba94174ee2c79d8916d76966e6f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:9dba6fecacab7fb755d4c635ce6f396eebff552211df1d6505b763672b22cf36
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:6ec50cdd35e48efd4dc6cc36b8d33b33af4047f78e89b619505281ec0d8ae682
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:bd80fd80c84355762c2cd3bdd6b444c1fe881e8a5f6c6a7b6c5e431b89d9a0ff
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:60f3b7b743489790ff36cbfb854cb60e6c2965917c57885f0865a1efcbe41368
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:8ece2a48bbff765d8212b536bc277764fbed052cc4d6f65b5a159ebc3c4f9b98