Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.23
Tags:

8-alpine3.23, 8.504-alpine3.23, 8.504.01-alpine3.23

Index digest:

sha256:b7e6a1dc4b5ca93f9b4b7489752c240ca3a9aea44c4a719ee8a544c11cb74271

Manifest digest:

sha256:e539c195372b74b3582c3d8a44a2e1bafcfd62c7be2a12312ac29224bac2512b

Size

35.57 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:24840aae1891f2c19d24a5eddd762fca2903221548a91dc682e35e8633f73800
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:3812d547fcef1af444ede68505f5f7ce223507df0ef36606c081356f94234349
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:d1a69f110e8382f47da01e8a4b261677d2cdc6236dceb563dbf173e6d4971e4c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:b828f8e701588b5cf1636acf7bd098557fd76d3213ff69e4a0ded905d465af97
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:346e7d5a63af0cf272d291c9ceb99e137108703b5b697f2339e5ed2b38df29e1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:beab49751b03433fbc129c550121933b02f00d699dcf3e079c9265c961411769
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:0c162dbde8ad5c3ff01396b7f529aa12a2024b1f9081d19bf2392ec90231e024
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:3a2bdaf31b0fd78244d7ac0e74042e9e60a032651766e8f6976171314157dd05
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:05bfdd1595df95f60c4c4ae4914b258c2fb9dca8f30567425d963824f04ef004
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:4228129a7e16afafd4f94aae2e9dcd8722659bf2f00fa0f7b8c91d69e73ee147
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:e953325ab2a0e58154de77143c8f7494c94333e2ef40a0541c4251eb3da896fd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:b6123830c954253a7fefaa04655af13211721b3c2b08fc7c2b3c2e93791f7846
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:d49ce25213744ec7b4b08241dc986b76f6801b4ecdd15da6c8b783b715ef6480
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:905cbba5d218b76aaa34159b1318e8cb4d74931a2d476ed9fd68cb75326000da