Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.504-alpine-fips, 8.504-alpine3.24-fips, 8.504.01-alpine-fips, 8.504.01-alpine3.24-fips

Index digest:

sha256:d1f91a66b032fdb536c90f7ef193fc21b1e1ce17eb935625b3f33a8404856daf

Manifest digest:

sha256:5177fce5e0c667e3b9694575e972e34df435719f47e6cb3ba6d14568db993056

Size

48.33 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:67325e49f79e22c3193e6142e535fbfd79c49fbc64e842bfd7ec49da92a5d8cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:7fe07c4de24c1c18d3f8883d17cc1c15c02d5b6bba2222524eece548e52ff949
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:f89a9ef66fa9e615bd339179e90ed9646b9123e5ee4cc6c9683a09a956bdf8d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:0aad53d7c6b06d02d9237a7ca561862f53732ecff3313b1c0ce1ebca146b03b2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:a6e7f43652caee43d5ea5288f64b8a2101772a4b65553298c361f47b2327e70c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:90a2168526f22ffbf5fa25d38dfb513a0a5097bd4aa5551d8d50a61df1484915
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:3516706a3eabba2589aca362808087ea48bf0facd53a00963910e8ab5b32bef3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:2725bf3b9775ff1fa9532a81f7e3cd7c99c5510d76b7263bb9059a2efbe84cdc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:0f0dc8e7b4fb32eb9a414b44d4ff7a608f50579ceee9e55d1c4daee9a5e9851e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:5fb3bf30749d08700590e4d3ff26aa8b33ca0d1cf253ee2302190cf71e322fd1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:6ac38cc12be32a60492d1cece36fcf8d7e6fbc4c620629ef03a8899036dbe7a2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:9ee5b39c5ee6ffc3b50de55f6615e0b55f47a13d5884f500fcc694ade84a3217
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:1c4598b3e9e28bda741408fbe41b60d91a80c984ab8a1182db080106c56c07a1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:a1021d8dde7c3f51048dc0eecb77541d22fba2d0f4e12fd2ce1fac1ce4661de3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:8b897e745a9c67ca754d3591ca4e29713c6ecfc759c9d09c7ad524ec56224ba7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:6aac32944a301f3360c66fb0494d94e7d156a2f97539d9fec4e1b874f4df77f1