Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.01-alpine3.23

Index digest:

sha256:812bec4bb65887a1d11644adb44fd6c94dbf449ccf4e9c1bad4fc86af4086f53

Manifest digest:

sha256:3bb4bbf48566b276e133138a593731bb7bb75a86fd8133829ad0ebc90353906f

Size

35.59 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:f0c0bfa6a4b2f9154c32073889c801488eceefda3abaa264a66671db47c71e29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:f3d58d390ae76ce80ac60cfcb10fe73b064e5fe3897e1119a4d59010dda65b1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:58651f7faafff54338f8e31bcca9e1a98759c331e103f3d0fe14fd120ade8ee1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:5ca452d7565093a2a3a205476a30505f36c2769b04123eebeebaaf6a92336fea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:40dd803917232415eb0e03fabcffb36ce7136b233c3aebfbb9764471a4920994
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:5ad1565cf1b8dd14223840d240700568556d5e54fb81be3bda657c0cfc32728f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:04ebf0bcfcea05ed1eecc4c64ae6216eb01ed30cd0816efbe3f6c41811175bfb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:b4e91c1e8a9d7bb6c45da78c438caafdb298e26d7e8271a2c9ab02846fd015c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:52ca4b2be9d9381977b05afc6708fdb89bbc999ac1fc689aaa190fd216d75b5d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:44a3cc1da8672aff2fc8b5a6b2dc9a5a53985561429e781732866ea5edafb32e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:15401e18ffaf695039cab8c3df40656fd2a7f7d82bd46a9650ee1ac7c5201786
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:48e31e97f220e7511dcf48a19e53d1fd4b7fd5c092751e37711d697d93806155
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:d0f477e1426ac527617911d63db2bc71a8942411849d58993b0fed3ec016b09c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:b7a81da7cf8c7f2d179451487884973c7b4531948620894302cbe834c03a152e