Sign inSign up
Eclipse Temurin

dhi.io/eclipse-temurin

Eclipse Temurin 8.x JRE

CIS
linux/amd64
alpine 3.24
Tags:

8-alpine, 8-alpine3.24, 8.504-alpine, 8.504-alpine3.24, 8.504.01-alpine, 8.504.01-alpine3.24

Index digest:

sha256:c5ee26d4f12e0dca8e88e63581cad7821935b4402ad1181067316bae559375ae

Manifest digest:

sha256:4162ac2870b0351c07d0f63496e4116e88d36bf21a98491f27beeaf6cae59423

Size

35.59 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Dec 2030

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/eclipse-temurin:8-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/eclipse-temurin:8-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/eclipse-temurin@sha256:1d37866249d7926367cca94100b8c277cfb2f693d681e8462e2bce3b3aec06e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/eclipse-temurin@sha256:681b87b1a8594b2153ab8023a076f0008a5cdc0a69d9645c1c280bc2f3c0d69f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/eclipse-temurin@sha256:f84766ec1bd5d2ee48ce56030b9a61d43090fa403ba5ed7eceee316790c47e2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/eclipse-temurin@sha256:502c4ebde9ce077bf161170eccdb4f3acefd47beef171e3ae064af6d3df8a925
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/eclipse-temurin@sha256:9db2a8d66aa0d8a5c8e890cc108355c726e8847e49b5651038d0b0e9a11cb5d1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/eclipse-temurin@sha256:bf69f12764d6b18f678ce387c371a2ab73fe125f1da2546beec57c2549bd0970
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/eclipse-temurin@sha256:9da564e008bc905623d69cde2014b7ad782f11918d4a51bbb9a4d9a10a149387
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/eclipse-temurin@sha256:883c165141c5a3d620c2b84277749a6185df43d77b07587b90b64ffea5c274c9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/eclipse-temurin@sha256:168fad490c33942f3cb273d99941d3763d7058c4821859efc5000135e421f083
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/eclipse-temurin@sha256:5482a89f5572bd53c82e60c80bb7280752ae9a6b0a89b9b9efc214125e19808b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/eclipse-temurin@sha256:30451b2872b9fbbba6a7a781f8a69392cea16279bc0a8ebc241472b9fa93f1e9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/eclipse-temurin@sha256:58b5825c5de5241625c5d83c77230fba1c33ef7695f0a570290e456fb6339471
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/eclipse-temurin@sha256:a2d6a14d656dc36528fe46297bbb195e67fd40607e42b9e7eff85e6b7e651f7f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/eclipse-temurin@sha256:818208760e18ea0c1aaf21dc59c23a905dec2a98a169dc7e96e204534bda156f