Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JDK (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-jdk-alpine-fips-dev, 8-jdk-alpine3.24-fips-dev, 8.504-jdk-alpine-fips-dev, 8.504-jdk-alpine3.24-fips-dev, 8.504.01-jdk-alpine-fips-dev, 8.504.01-jdk-alpine3.24-fips-dev

Index digest:

sha256:17a857aed9628e1b21aa5c1ace8fa15a57d5f81fd2515f0a5f7bc6bf859625be

Manifest digest:

sha256:fb8b95ac9b9182474e19b559aec727924cc4c8c39e1383526f34853629875bb0

Size

101.80 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-jdk-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:5466649bfd3825785681dfeeb5f3046c231b29f8735192f809b7d6ac869dfa25
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:ef9bede952222e4dd127077e4c3afe9ce4475e5cbd4477a732b57a0babb3842e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:d9723727a804718bdc0dd36ca01ce0160145ef69c3c1391f1c58fd16a402b6d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:16d407dd647b8f4a6b50da741c5371e93ae5b24c9195ab6cb778bab256dd9179
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:9ea5a3d8fcdc0e4bfa532d0b2940e7beec6519212d82a09f0c625eed3dfbb26d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:cd90d4c652b9a251570db3aa9ace684b64988b28f502023af1516f25a04dec4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:e22f7c22588421119f427a16fe6ddf6e536a48d8ec93c1def8b2179dac7959ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:395bca1c13048c51c5c9881513cb5fcd3065cdd2c484db6f42d7228be1b66bcf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:4db64405c16b8c8db46285aa1653558ad574cf00ed5c765f575037b3e7114155
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:7a9ad6c3d77a35d33985a6fd5341b161fe67b0fb568c52a132151f13c5c64597
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:de243ab703686dd9c47e969a7be3d06a946d5e779db196de31304ee6ef49a276
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:ebba63d1db43cce174a7179d17770c2459a6beb78c095768d16bc0d9e26b90aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:91fb10eddadebcde67e4aa298f2cfd9fab8eb299db064c13e930cd306f8cad96
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:755f17e82f54ed4ad793dc1b6b7532e65d421f01137394fd9a17ee2167f878c9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:0c88c071acbf05689755b4ce6601ce21ea1f740e765671604483431d3260cc72
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:661fa8d605e65e3001e7be7d6b139db1760b985686a350d3cab3c266e12c4789