Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

8-alpine-fips, 8-alpine3.24-fips, 8.504-alpine-fips, 8.504-alpine3.24-fips, 8.504.01-alpine-fips, 8.504.01-alpine3.24-fips

Index digest:

sha256:67a79a50bdb9ddf7440a3732390036544a08720570005b8fce4235b33cec614c

Manifest digest:

sha256:f8c987ebacc71a27545585974a9beee758a295cd4a2ba3fd453fa024c35c2726

Size

47.64 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:25a79472586dd35766ed3f8e559d34f326b30dfbecb83310af88d73200113a90
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:ccee68ccf59ffcce39275b9a529ae6d24ed3c3e0b1edbe248fc32c80404997ea
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/eclipse-temurin@sha256:09bf521505a8bee5c467a8da850fac0af1da9f90663b57ea8e88e9502e50dc7a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:97355dbbff5037dcadfca248f74ec9afe2c814d0150719ec3462f11bfaefe62c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/eclipse-temurin@sha256:f26efd8b495d04684b3826fff1a001ff728dffebc77a0f8b118cb9a2d3600681
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:8f32424ee165c4a9910e815ab5320fad738dc1d2a27d1debf49a04f3615a523d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:d678ecab09a85124eeb8970e1c492f47d2d6e54b91ef7473b9e0891c87bfea52
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:789dcfa3994c5640a36edd48c3bb509fef20da0c49f4abcfc1c933c190579dd6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:3013b9771fc79253eae97540d94bbffd7b4b3d8ed5bcaae36355d7228d792166
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:2751d2a11138db615b56b037c739778c4f160d279e292be9cfd58198622bab06
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:1bc2b0c3e6a5b99edc8ecfd01fd87cc01e761df0febe8326db5b06a91800aca5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:d30d2d8d44525fb046fde5f0ea8208c04d61c4dad3327fbc509087a2e4c8e9c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:540535ff46ec9729e61548e4c3a0d5a3afc7da9eaff453a7d20e77acbaeffc91
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:545980b65a85a01e37593d3ce1984ecfe1c586e1cbf2d23fc9a2f6440090b4f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:870c8c777bfe142e71c389f20d9f743b327c8102e06d5570013f480b77c134f2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:d0758fc818f48ab4b0480c5a1ee210ba8dca69b34efd052df871511553336ba4