Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.01-alpine3.23

Index digest:

sha256:36fb4aecf0ffdfaa45837a77559e7ba0089236cc054fcd2cfbb4f5591296d4f3

Manifest digest:

sha256:9732898417c82dd4bd8eb662a1d82d8d755a93c9146e2d05411b368bb88f61b0

Size

35.59 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:ce08f28ad7f34b0a980d1ffa8760176ab3244e8c7fc744bae122997983718001
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:724032f9397bee62b0ee992c6e36009b6461ee2aa886d0fb40becd0646b02805
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:1f74fde85787cb2eb56e43985372ec1fe1b4793dc24be9ec3ea16a73220e8669
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:ef4296612ba06ccb2ebc4928a4a6184bf9752cc32664f7cf0b228402c83db8cf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:bcbd2b73dfe5921462159a4089fa7a1c8a5fc489430ad2c31262c80004d7fefc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:83c7679c5f0071d10dbca83d813aee8db782141fce6aafd8b91baf9c1a125b91
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:44b2ae1235808f4b223cdc6586b9ad3491998641a089f0ba50167235437a5338
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:1d6f6bd7619c900e6d629ca67d72faef81cc65327d52be0ae1547a0be2122332
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:905fe3fc0d4e0d0c1fdf3ffc036457e75f72999b677b58e2840012b7fac61145
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:d72298f1aded9d8e69ca748a9f4a53b3ee973bb0b8afb845851024277c8dabf8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:a62bf50e845f66106047d6ddf5b184c48704eec1b563eaa5eca9e0a466439e3d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:ca7930984d507390a68f3475a2cd44373d18982c09c1b659a3a8dfeb688fa96f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:020507f05ee2270e02526820fb56e3cc5c20eed3c90ca27ace5f3c1234cbcf21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:85f4d40109f075a019b04ef75cea658d5e5df41fc92ca4159aff9d1d76e0b8c1