Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 11.x JDK (dev)

CIS
linux/amd64
alpine 3.24
Tags:

11-jdk-alpine-dev, 11-jdk-alpine3.24-dev, 11.0-jdk-alpine-dev, 11.0-jdk-alpine3.24-dev, 11.0.32-jdk-alpine-dev, 11.0.32-jdk-alpine3.24-dev, 11.0.32.9-jdk-alpine-dev, 11.0.32.9-jdk-alpine3.24-dev

Index digest:

sha256:8f7372b30182f78d7508b0dfd77292cb3e5848e9dbc56bc596c3aa1f0fd7c6f7

Manifest digest:

sha256:0d8db202990933292d90e20fe1d2ce6f5e9d3ad871e228ccbe33f83025d18529

Size

174.27 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:11-jdk-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:11-jdk-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:cd53f018aa2d24c6411b52e57de5aa970a23171ce879a8f5a6ced5305453c262
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:b573527b58d6f72f76648b4d0d4bbc9d42d127b9d997135ba4c3dcea6585ded8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:cdbd2c511c6cd9526bb107289d5366d037e77af205f62161a554c7b7aff14d3b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:ea986988f1849b6886cfdb3efb6813201273b1135caf280a8a897df8774fd178
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:8aa9ac7664c4cfad3e273077eb63f003bbfc5f622c50eca674be0bc041c9648c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:9b96591170a623173200fa40e1b8e15da6d2c41eeadc3db95d0354c7817cb32d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:98d06f7341be2e8f92e359feb7486f8db95ef793696a9aca19cb90cd562ff6f9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:ab91652194d3c7d245221f10b87d9409d81fdcb7d4d400b4b42841d956faeccf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:e91185391022e4d570eb3cc05bc56360f154ec8e8fee6630afe2efe95d51aec7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:f662a96eed156e1cf3654e7fe6b0cc4afe97d3e7f1f9f3bc0df6eeca80e6d127
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:b8a477be212372bb79bb64bb63925fe656c1c836b7cf0008696557760f085446
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:9e6ce8088c48764db0b69a5e3275e749e3b216315efb8dc64164be9caf956704
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:775a54be01202f59fc9bc45e83f993ddc99286b7a4428521e60494dbbfbf2270
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:ce675c043d4cc1de7eea3188d6051e41aefb4e7b29be950683b8d2ce905d5984