Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 17.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

17-jdk-alpine-fips-dev, 17-jdk-alpine3.24-fips-dev, 17.0-jdk-alpine-fips-dev, 17.0-jdk-alpine3.24-fips-dev, 17.0.20-jdk-alpine-fips-dev, 17.0.20-jdk-alpine3.24-fips-dev, 17.0.20.8-jdk-alpine-fips-dev, 17.0.20.8-jdk-alpine3.24-fips-dev

Index digest:

sha256:0144735330dea4d666ad552d54217c76d9329e774dd77c22701333a86ed1f754

Manifest digest:

sha256:561221cf600888b5e6f3f07f020ba88b1b9cd7b1890f7c8b61054d779b78a0f1

Size

183.82 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Oct 2027

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:17-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:17-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:4ca19ae137fb4a3277531807addc85ac41bb0496a82112c047c4a0017b391994
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:afc6514b220299372746231d36f343089c1c78c0129a013ff6a56f09e25fda7c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:5c05b314d3a3d4fd7c1d531566a26e6ea76c17b65a44b427b95c3f1461e2ae82
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:9b7602792dfc8fea630a3ad3e89268a5d0a3d17871618109268dbef9a89b64f7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:e6cb94ee21e96878d109a8e39749bcd973c84d55fd3bece9e421eaa1a4f968b5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:0fe5965a8dda427e91c620674d0b056e996bc0483b3185b8bf33a52e98462429
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:88214679ac49e0155ddd654f8c629fc79a83ae6fdac2cb3092f7cee778365100
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:fc3a8f463cc9314e40eda076cfc8ab22331cb40926c7695716413500f33a3430
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:1bd1a80a23e2a0effe75c4d253f06ba80c92442bfe719c2b6fbec170b7fdf6c0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:9a779584670f14bea09c53633c3c44017d6f1c79cb0ab724fafa39d72ef65227
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:1a45f973e6244fd12de6536ea5b5a8be1fd4dbad978a45ab3892b07c5daf628e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:d9ab65af7c6810f9e446341cfd7a8aae4ef1b9aa106572ce011c35c18787a443
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:921ad4fc69dc2cb7c30cfb27bdc4b0c3c1471bec3527b8f0396263fbec5ae637
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:e7b4806df6b83fade67862d5201a8d53147ea354851e064b60b75763ef1287e6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:7af79b44d2328ac11a9f3fd5b74f80586713964904a0c11050705b32e271399c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:ff447f33e5b982971a1b927c1a185fc3a54a0568bc12defcbae89b48a19575b1