Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JRE (dev)

CIS
linux/amd64
alpine 3.23
Tags:

17-alpine3.23-dev, 17.0-alpine3.23-dev, 17.0.20-alpine3.23-dev, 17.0.20.1-alpine3.23-dev

Index digest:

sha256:23307f00f9fd19847d2e89e5190cd1f59630d3f0620faa112d74217130ffb004

Manifest digest:

sha256:a2c44e3d4e37ee12209b837a159ba6e3b320e2ea818a4b3549596bc24b36ffcf

Size

39.90 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:ed9772bd0a968b05b6f5c9d824f939bbcced897ae62805bcf4505fc3f49664a7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:abf103cfa64d078f0d3fb8703bd68222536d80df7f4268daa2f88d27e386feb0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:70b40bd04c8ce20d019cd4b9266a83bab0e791e1781392da47175eca2c9f906c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:02157a38a61b0a8145a14aed58c4cc357d89dc140a3fee7ce6f2d6c0c6b8e7ed
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:34226a4bff3032e64f323c00b439ff592bfb377a73cbd0eb64ea57adaf39aee0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:1b742bb21d48338e62bb3468f27dca6816f101b13b9881b8dc7e7920d487c22c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:8cda1c0781b84fe0f799938771bfe8ef129528bf0536e4c4a6e2180f138e6395
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:7bdd73b28f07f196afcd3ed29422a9cf27db8c95a110de9d4b0f7e29aefac15d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:b2ba262adaa586000b1848f6bea9c72333c3c35880964b091bde1617a9979a50
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:24a5786fded89112a140fd97bbab488e7f745da982e39235606605b6d6e19dd4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:db8ad788a9eea107f8a38a6e426cb0db7e0547c2ed3a99678ff442d4a0dad6e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:09acb7d04abb57c79eec1e3963aef002c653056106540db3fb0527ae7ea2858b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:47ccf410e95fbe1181cc53705600ac84af9387a7c1a558d53ab17f97e8f4d3b2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:28253bad633e77c1b0f2f040c23478513d314cca0343c26ab4dcde2f517b242d