Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (dev)

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine-dev, 8-alpine3.24-dev, 8.504-alpine-dev, 8.504-alpine3.24-dev, 8.504.01-alpine-dev, 8.504.01-alpine3.24-dev

Index digest:

sha256:c1b21dd9bc902964119554660c624606c22c7b5d6e80a73c1438783ee1ee506d

Manifest digest:

sha256:401ee78c918f62f161263c3951a1c002f76519a452871ada0460eefaf4d10716

Size

38.61 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:a9da9003ba1443cc94ec90b7d411344ad07c1e015d68e4d989cc10b20c864c97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:f70cae92cb641b5145b08e7378629137978a0c52dbd890ec9c0ba427c2fb7b3f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:c20d0016ca74db85f28a1e018534b55fa7c2d7f23aa21bb701c7aa17e97eee57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:7c3b18dc804df11f9c44739ed9ba48b8eff417c4dd38bd379e8abee0b27ee740
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:1af90cdcb05017dab0f14744ffc68910e4b195ae4be183b1816f908a0fd876f7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:f58aa728cc874ce40aee76dfd613b32c0910d41bf28ac204471e30ac2834c704
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:14d197cd6f33e5ef54edd4bf1f62013e31be090e0b69a98335eceb752c49ac35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:eb7f84705a7db33a33995864b3c8e57a09d14980acabb9af86d72dc9238e2f24
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:b69239c51b0d69a77f375b262a128c2680d841b9ea3fc2290fca05a9249a40e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:6357b6979dae031f65055cce3c97326a2fde03d6d9d19e4768e3b55a64a4414a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:bfb08401926ea0f1a9f34d5b685dd0c34e02ffc4fa7cfb35df5a8cc377e0c203
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:943f81ceca83d80dcf66ad169c95585439445a9a8504a040ce5b81e12cbc56a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:5e1381cd523b82a5e165ea6f64ba700d839fa9fd16606d6c29d93d5672ecd0ab
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:bc5fb35343bf3cdba35a858c1987c50305ad0e735fd23d7d35920b327388b932