Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 25.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

25-jdk-alpine-fips-dev, 25-jdk-alpine3.24-fips-dev, 25.0-jdk-alpine-fips-dev, 25.0-jdk-alpine3.24-fips-dev, 25.0.4-jdk-alpine-fips-dev, 25.0.4-jdk-alpine3.24-fips-dev, 25.0.4.7-jdk-alpine-fips-dev, 25.0.4.7-jdk-alpine3.24-fips-dev

Index digest:

sha256:51b3d6f1ee809677c795d79f336470766a698f59467082ac375c07374dbbdbee

Manifest digest:

sha256:bac3a4f6e96e74a28bea1edfa96e6b11f4626be11f085ffc29b6ecae011bf67f

Size

132.86 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Sep 2031

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:25-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:25-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:9f6a9667f66e71969c8b1f4797f83e425d11662d604322a662b65a9d6d204be0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:ffe0a609d440fd97c9a310624ee0597105bb8463c29fdc118896112b1983b880
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:2668979f86255d6642c6a9162ddb605d1f295559256904aad55f7126a4e0cfb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:7fa8b930a4a655420d92ff3702f3135c35b8f3df0a18ba3cc7bada21a36f1a8b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:d9eef31680598fe3d4955ac48c971a1154a42db6d20176a3ba50411df9b44c45
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:49b21c36f0dea83282a6864653a71376c99f02668bcf8181863e2992d144252f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:0dbd89cef94b1d59c16fc6e0dc0a9ba7e05e28dd306c99294eb0431761a442fc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:6cf8ed903b3cbbc4aba415b5b8f1230109d5acc96df7dd941ec30f46db3435c1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:11fbc74bd2580a33d6cb225c0b7a053f6643ed0c1319dfb2061f23ec0facadf1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:6e211356ef56c52ac39519909902babb65caf4276d6a172631777564c13abb1c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:f22589afc04706265735fd694bdf40d43b5631f056e62dbb341be9f25375cb59
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:7350ed02a269df06c7ce13ff30b9764ba85ab121162da6a8039e4180f001c426
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:5123db36df4fe6631723534721810d78791faa5d5966c423e65d74cd0be50901
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:e46f4d37bf9ab2011e06131ef16dccb8b34b308f7a203796352ef96c61d85538
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:0ac6628be6c42d13b6354644dbc41eeb83c5388bbdd7e880097e7cd5bea64596
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:72daacf3e67a80654bd28afa1086171d22a5b589c1718a66266f00999d13e80f