Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JRE

CIS
linux/amd64
alpine 3.23
Tags:

11-alpine3.23, 11.0-alpine3.23, 11.0.32-alpine3.23, 11.0.32.1-alpine3.23

Index digest:

sha256:9e0886fe0fac9ea68dba723a4a1e354729d5a880368a489eb40f9acc36040683

Manifest digest:

sha256:384dd35bb974e77936e2c463c01a2fde99bfcf265debccb079a4a032e07f4e9d

Size

33.84 MB

Last pushed

10 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:08d48c5f9b17ea4edd0a4d40e0a7ad978d197a1f81d32510830317cac672bd74
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:61c619caeb4e49193a35aa9800b7f6477599c9b61436dd6f01a063ecb11654e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:b2cabd1f7bf3749d440e953294bc6a80b470a8a7de7beb5f6b5279d5262a5831
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:203627c76ae47f6a44e24661b5cb98501c86c2f6aa8bf068019d1cf14e50f54c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:396bf3f051b2798e7ec4abf226c4d3c7c0497a0ce2136df6ed5c010c1fbed508
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:30387058343bc90ba323466c5343d4c9204c11fa7bcefb681d8ada78e8454018
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:0579ecfd87c0e162acefecfe6f0b2420b913090eb5bb17c74df68885a2855683
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:8d39e7b07acdd2799795126acfa66915ccb42d16194e963b00c34fed3683c4fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:18fe2b5c1b53a12145652abd1c3259661157a286df643aa760a2cf1eb36a7835
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:dda6f52bd52049903b80c1f7518ee5e97924c83066efe97c098ea844aab3f6b7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:1f6b230f513c6d42bcc3ac76f5830561e88ca4bd45a78742fe9e430495554e65
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:7fc392a0a2b9e6eea3be3fb891b0b39c6399bc10b5d86b8441e7e212b3185897
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:0cb87654d51f9ce0dc5774cbd9972dedfd99fb0f617aecaa530077ac07d96941
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:4bd00048f9eac7cccef1d05d14c770eb294084106c1005ce8e7e56254fd6768f