Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 26.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

26-alpine3.23-fips, 26.0-alpine3.23-fips, 26.0.2-alpine3.23-fips, 26.0.2.1-alpine3.23-fips

Index digest:

sha256:094b13dc23222a386cb919d3d57b3fefcb7d15d14ae0db2823d28fc103161777

Manifest digest:

sha256:489a8a50e46bddcc334a84cffd65660265c0b9b8adf83d39beac65a62953c9ff

Size

61.88 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Ends Sep 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:26-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:26-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:7598640256ea642fd0cef57f9de88ee3692f63a8ead3c4f663fa7f4975b4dbf4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:5eb19b212860a214c4530c636a346a4e93b9f14d6dbcd772eacde0419bdb5d7a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:21b3cf829cf49916910a47263704f4f44bd524e77336f1fee9aadf89d9a06fdb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:43f4326ba665eb31f29cb3007927f7076b5dbaf7f4f84d5bf49726feb84d7050
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:5fdb92b336bca6cfbebcf8541583a216280f5177f634c5127dc6a3ac61b9f896
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:b46fcb3be2be55d15ef1caf00c489a945d5fcb00ddafa99946e15cb52dfaede9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:0a7cd986caac12f448b8979dfd88c2b654d735136d0e95f7f82c9194662bd65e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:92534a8b7e26a316bf6bf6767014a0d594d746a633705590084c9ded928330d2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:3ea329a874577ba77ec82f51fe91bbe38597993f166077656397d16d0b37198a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:15aa1565c21d73cd3a39e0ccd581b2bb80221485e259e93952d18257ae828eb4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:fff33842558a7bd5ac23727f26b0154f5877435556ae892f3f58a0f5c699615c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:cd869d32db431149ef278d3ac475ab0f90eab419c8a60a39346316e4811afc67
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:08b722d129d5b23be0e75128fb2830f10bbe335d85e033918db4984ffdf17a0b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:af6a92cd5d253c475019097859e565008aeb00c824defb8320932a10bb8c93ad
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:e66635f213945331de6d8779996b407964fd9fc594e0dae23d4ab9fadfff7796
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:19e3e8c799d53921095f0ccfd6800e1b44681fb93347e5b6f263cfdfcfbefb3b