Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 21.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

21-jdk-alpine-fips-dev, 21-jdk-alpine3.24-fips-dev, 21.0-jdk-alpine-fips-dev, 21.0-jdk-alpine3.24-fips-dev, 21.0.12-jdk-alpine-fips-dev, 21.0.12-jdk-alpine3.24-fips-dev, 21.0.12.8-jdk-alpine-fips-dev, 21.0.12.8-jdk-alpine3.24-fips-dev

Index digest:

sha256:33e50c989427fb685ea6e40a57021f5eb1f14492e78a3bd237a007c65bbbbea3

Manifest digest:

sha256:fde6a26cb1f44cb1a482c2a4ac7ef3ac9bfb744424bdfc83bb61baa0e5b1f296

Size

195.68 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2029

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:21-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:21-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:8595b692246eff86e22acc1d8619d11b600105062d5c3ea3b1df2d8e056b8736
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:9283d24466b1bfab1e875f264eaa46d5963980c44d6d50033f19424bee1220e4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:a34badb03d664d41495bdb5491b35dffa59496d7fd69d9992fdd349f1867407a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:55e1638209bc45d742b0c02b45c2814fbf10817197b7adc43b67b6b75edf35ed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:aff209d48b8f517c9e8c5ad3655dc4b979d5d2facc564b2d6113a8fa51deb147
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:deef245bf03b9f5e4efbca463f35516d59af13f236459c31f10bbd6e38d1d683
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:6614b5b06b819682a8c160c0726e33c4e2844e11f3202f43a8580d73999898a7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:66d8d8fc23e45b9298b4d58737b03e9ea9e8e5271fd80c4bc2de6eceaccdd43d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:7411e8f33ee336f1cdcffc1810c2d22fd04a4cba76bba884555909b3aaeee119
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:861d96e33a736f1165b91bcbd9f2890db965628946d80f5ab266252c0e605bc3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:4a14be4055184a406799753cb53f0c0190e7655716ad846525bcfe794842de57
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:a595cdaa14f388dc71d1c8a0de4a5d59f32ccf4c99796bfcd2a44ce084c0710f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:6b76121e9e7974a98d69bbf61797d29ed115679e5bcab9adc546d6226771d3aa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:70d5fec14214723445ef4a1f493aaf3569347eaf7d75e67f1bca6ec1a07cb9f0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:38f447cc7098cb52287c00cc385f7de368690348fe5c8037bc476cc4ca091bdb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:9bbaa7548594f66f998c0ab75f30d17b4ab8e2d3b330918170a015085b263f6e