Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JRE

CIS
linux/amd64
alpine 3.23
Tags:

17-alpine3.23, 17.0-alpine3.23, 17.0.20-alpine3.23, 17.0.20.1-alpine3.23

Index digest:

sha256:2487aff532d1fc5a1e9875fd043f9790a7c9e0fa5c95375b435144aba0107ac8

Manifest digest:

sha256:74b5ad33e64393fd6964b3c1c66e122228d217f7851194b3f6a8f3188411cb6a

Size

36.87 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:09c971c6a007fc5c026ec3f8fe125c6a1fc2c3c258972b4222f24cc328bc9a3d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:174d4ab865a9d4175065efeb62d54c72e7ca234c863137cda1f1b80673410bb5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:9553d2e49897022c58706afcf1edfeca945a7051a81fee84a2e52a9b1a1ca590
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:03342ae2aa012da04497b7907035a81eb21664416cf8bf19eda3dcb1cc1fb7fe
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:1036abb8a2730fa8fd603cb17f3915cdded2b878e6401ac370a4f34e06b022de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:7df0a56cab98840531998b89da44b4458d69466d5eb71de49c64aa97ee716e71
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:cfc104926d0d5d9e61360bd09fddc087860838559bfe462e7ab2aaa185b93db4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:22f318876c35d69adbfc32dc8424a83f02475474bca4af5be568df8744988b57
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:070b1c4d64f1ed92761ed80cb20dcb1d585561e3888313c7a9f2cca31c21f36b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:8a4387b94d8a17330c41b84ff8ecc6743205ec255dbb2a08dabe565a032b2312
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:b85b52b25ad4615398bc8b07cb299114cd431638429083a975b072f820709fc3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:4faee9729a363fa1acad64b079b436f390ea11c4375cd591bd8d394f5dff6771
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:60bcdfcaa04cde31ec86344f1d47f8f1d566487d168bdb22789ceecaa7e0958d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:09821a35c6512acd0bcf49f826b827c5f1bbdb2320e74e814d1595da40a5dc5e